Skip to main content
Create Free Account

Contractor Compliance

Contractor Management KPIs: 10 Measures That Show the Program Is Working

The 10 measures that show whether your contractor management program is working, and how to set targets.

  • Published
  • 11 min read
A facilities manager at a building-office desk reading a printed report with a pen in her hand, a white hard hat and an orange and navy hi-vis vest hanging on the wall behind her and a car park beyond the window
The numbers worth keeping are the ones that tell you what to do next.

A contractor program can look healthy for a year and still be running on luck: no one was hurt, and the register is current because the one person who opens it is careful. Key performance indicators (KPIs) replace that comfort with numbers you can read at a skim and act on.

This guide is for the facilities manager, operations lead or WHS manager who owns the contractor program for a property portfolio or a transport and logistics network and has to show it is working. It gives 10 measures. Each has a definition, a formula, where the data comes from, a target only where a published source supports one, and the action a bad number should trigger. A tracker to download is near the end, and the examples are made up.

One clarification, because search results mix them up. These are KPIs for the contractors who work on your sites, not for the contracts that engage them; time to signature belongs to legal and procurement. The process behind the measures is in the contractor management process, and the screen to show them on is in what a contractor compliance dashboard needs to show.

What Is the Difference Between Leading & Lagging Measures?

A leading measure shows whether a control is running: reminders going out, documents being reviewed, a gate checking status. A lagging measure shows what happened regardless, such as an expired ticket found on site or an injury. A 2017 report on measuring WHS, published by Safe Work Australia, puts it this way: lead measures tell you how a control is being implemented, and lag measures tell you how effective it was.1

You need both, because each misleads alone. Serious injuries are rare in any one contractor program, so a quiet quarter says little; the same report says that having no lost time injuries does not necessarily mean risks are controlled.1 The 2024 WorkSafe Western Australia guide, written for petroleum operators, gives a useful test. If the leading measures look poor and the lagging one is fine, it is likely that the leading ones are too far from the control that matters. If the leading measures are on target and the lagging one is poor, it is likely that the control itself is ineffective.2

The 10 Measures at a Glance.

Eight are leading and 2 are lagging. The next four sections take them in the order a contractor meets them.

#MeasureTypeWhere the target comes from
1Time to approvedLeadingSet your own baseline
2Share of active contractors fully approvedLeadingOur judgement: every contractor cleared to sign in
3Induction complete before first sign-inLeadingOur judgement: every first sign-in
4Expiries caught before lapseLeadingSet your own baseline
5Review turnaroundLeadingSet your own baseline
6Sign-ins overriddenLeadingSet your own baseline
7Overrides with a reasonLeadingOur judgement: a reason on every override
8Expired items found on siteLaggingOur judgement: zero
9Corrective action close-outLeadingPublished example, with limits
10Incidents per million hours on siteLaggingPublished comparator, with limits

Before the Contractor Arrives: Time to Approved, Share Approved & Induction.

1. Time to approved. This is how long a contractor takes to get from invitation to every required item approved. The formula is approval date minus invitation date, reported as a median. The data comes from your register or onboarding records. No published target exists, so set your own baseline from the last 20 contractors you onboarded. If the median climbs, split it into time waiting on the contractor and time waiting on your reviewer; measure 5 covers the second.

2. Share of active contractors fully approved. Take the active contractors, meaning those with a current job or a sign-in within the last 30 days, and divide those holding every required item, approved and in date, by all of them. The data is a register export filtered the same way. Our judgement, not a published figure, is that anyone cleared to sign in holds every item. If it falls, list the contractors with a gap by their start date: someone is about to arrive with something outstanding.

3. Induction complete before first sign-in. Count first sign-ins where the person's site induction was complete and in date, and divide by all first sign-ins. The data comes from induction completion records and the sign-in register. Our judgement is every first sign-in, because a gate that admits people before they know the site rules has no control to measure. If it is lower, the induction is either not assigned to that contractor category or not enforced at that sign-in point. At a distribution centre, check drivers and one-off deliveries separately; they may enter by a different door.

While the Paperwork Is Live: Expiries Caught & Review Turnaround.

4. Expiries caught before lapse. Of the documents and tickets that reached their expiry date in the period, this is the share replaced and approved on or before that date. The formula is replaced by expiry divided by reached expiry. The data is the expiry and approval dates in the register. No published target exists; use last quarter as the baseline. For each miss, ask who held the replacement and when they were first told. Late notice means remind earlier; early notice and no action means no one owns the escalation.

5. Review turnaround. Measure the median and the longest number of days a submitted document waits for a decision (decision date minus submission date), plus the share rejected on the first pass. No published target exists, so agree a service level with your reviewers and tell contractors what it is. A long wait means the queue has no owner or no cover for leave; many rejections mean the reasons need reading, because a bare 'rejected' gets the same file back.

At the Gate: Overrides, Reasons & Expired Items Found.

6. Sign-ins overridden. An override is an entry allowed despite an outstanding item. The formula is overridden sign-ins divided by all sign-ins, per 100. The data is the sign-in register and the override record, such as an app log or a site manager's form. Refused sign-ins count only if your system records them, so check before you rely on them. A rate of zero for months after go-live can mean the gate is not checking. A high rate means requirements and reality are out of step, or renewals are stuck in review. No published target exists; take the first month as the baseline, then list each override by cause. Review queue: fix measure 5. Expired items: fix measure 4.

7. Overrides with a reason. Of the overrides in the period, count the share with a named approver and a written reason. The data is the override record: an app log, a site manager's form or a register column. No published figure exists; our judgement is that every override carries a reason. A climbing rate usually traces to one gate or supervisor; a missing reason goes back to the site manager the same week.

8. Expired items found on site. This lagging measure counts contractor workers found on site with an expired item that the check had not stopped. The gate cannot report what it missed, so someone has to look: each month, pull a sample of 10 people on site, at a depot or a building, and check their records against the register. Our judgement is zero, as a policy rather than a result. Each find is a failed control, so ask why: was the gate off, the status stale, or an override used?

After the Work: Corrective Actions & Incidents.

9. Corrective action close-out. Of the corrective actions raised against contractors by inspections, audits or incident reviews, count the share closed within 15 days of their due date, and the median days to close. The data is your action register. The 15 days is WorkSafe WA's example: its guide shows a target that every action is closed out within 15 days of the due date, and every audit non-conformance within 30 days, so it allows slippage past the due date. Set your own window. It is a guide for petroleum operators, the targets are marked as examples, and it says management, not the person doing the work, should set the tolerance.2 Escalate overdue high-risk actions to the manager who engaged the contractor, and hold a performance conversation when the same contractor keeps missing.

10. Incidents involving contractors per million hours on site. Choose one definition of incident and keep it. The formula is incidents involving contractor workers multiplied by 1,000,000, divided by contractor hours on your sites. The 2017 report uses 1,000,000 hours as the base and says to state it if you use 200,000.1 The incident register supplies the incidents; sign-in and sign-out records or contractor timesheets supply the hours.

For comparison, Safe Work Australia's serious claims frequency rate for 2023-24 (preliminary) was 6.8 per million hours worked across all industries, 9.0 for transport, postal and warehousing, 4.0 for rental, hiring and real estate services, and 5.0 for administrative and support services.3 Those figures count workers' compensation claims with at least one week off work, across every worker in the industry. Compare only incidents of that severity, and read them as a reference, not a target.

Small numbers swing: contractors working 60,000 hours a year (made up) show a rate of 16.7 with one such injury, and 0 with none. Report the count and the hours beside the rate, and cite lost workdays with it, as the 2017 report advises.1 Review each incident for which of measures 1 to 9 should have caught it.

How Do You Set a Target When Few Are Published?

Only 2 of the 10 measures have a published figure, and both come with limits. WorkSafe WA's are examples for a different industry, and Safe Work Australia's are claims rates across a whole industry. 4 more are policy rules, 'every' or zero, which need no baseline: measures 2, 3, 7 and 8. The other 4 need one: measures 1, 4, 5 and 6. Run each by hand on last quarter, write the number down and call it the baseline. Then set the target one step better, at a level you could defend to your own manager, and review it at 90 days when there are 3 months of data.

WorkSafe WA's guide adds a point worth copying: management, not the person responsible for the activity, should set the tolerance at which a result is flagged upward.2

A Worked Example: One Quarterly Review.

All numbers here are made up. A property manager with 14 buildings reviews the quarter. Of 118 active contractors, 110 held every required item, about 9 in 10. Of 40 items that reached expiry, 31 were replaced in time, about 3 in 4. Seven of the 9 misses were insurance certificates reminded 30 days ahead, which proved too late, so that reminder moves to 60 days.

Review turnaround was a median of 2 working days but a longest of 11, because a reviewer was on leave, so a second is named. There were 6 overrides, 4 with a reason; the 2 without one were at the same basement gate, and go to its site manager.

At a distribution centre the monthly sample of 10 might find the one driver whose licence lapsed last week. The question is the same: which measure should have caught it?

The KPI Tracker: What to Download & How to Use It.

The KPI tracker (CSV version) puts the 10 measures on one page. Each row has the formula, data source, owner, target, baseline, previous period and the action a bad number triggers. Fill in the baseline column first, from last quarter, and carry each review into the previous-period column at the next one so the trend shows.

Give each row one owner, and review leading measures monthly and lagging ones quarterly (our judgement), because a handful of events moves a lagging measure too little to read monthly.

Where ComplyFlow Fits.

ComplyFlow is contractor management software, and its Help Centre describes where several of these numbers come from. A Requirement Set bundles the documents, training and forms a contractor must provide, and the status shown against each supplier and worker comes from it, so the status that measures 1 and 2 count is set in one place.4 A document category's status depends on its review and its expiry date, and a grace period can leave a supplier's status unchanged for a set number of days after expiry; decide whether measure 4 counts the expiry date or the end of the grace period.5 A profile with outstanding requirements for a location cannot sign in until they are resolved, and some sites offer Sign in Anyway, which notifies the client.6

The Live Access list view filters by name, status or company and exports to CSV, and the Sign-In Book is a historical record of all sign-ins.7 A site induction runs at sign-in when it is due, and its completion is recorded.8 The reason for a rejected document stays in the document's history.9 The workers list downloads as CSV with an Alerts column.10

These articles describe no ready-made KPI report, no reason field on Sign in Anyway, no record of refused sign-ins and no hours-on-site report, so the tracker is a spreadsheet fed from these exports, and override reasons and hours need a routine of your own. See also contractor management, site access and workforce compliance.

What to Start With This Month.

Pick the 3 measures that are cheapest to run today: expiries caught before lapse, the share of active contractors fully approved, and overrides with a reason. Run each by hand on last quarter, write the baseline into the tracker and put the first review in the diary.

At that review you will know what the program caught, what it missed and what you changed, with a number beside each: a better answer to 'is it working?' than a quiet quarter.

Sources

  1. Measuring and Reporting on Work Health & Safety Safe Work Australia (O'Neill and Wolfe), 2017; read 6 October 2026
  2. Health and Safety Leading and Lagging Performance Indicators: Guide WorkSafe Western Australia, 18 January 2024; read 6 October 2026
  3. Key Work Health and Safety Statistics Australia 2025 Safe Work Australia, Released 16 October 2025 (data 2023-24 preliminary); read 6 October 2026
  4. Onboarding Requirements ComplyFlow Help Centre, Updated over a month before 6 October 2026; read 6 October 2026
  5. ComplyFlow Status Guide ComplyFlow Help Centre, Updated over 3 weeks before 6 October 2026; read 6 October 2026
  6. Signing In & Out of the Live Access App ComplyFlow Help Centre, Updated over a week before 6 October 2026; read 6 October 2026
  7. Live Access Dashboard ComplyFlow Help Centre, Updated over a month before 6 October 2026; read 6 October 2026
  8. Live Access Sign-In Options: Confirmation Sets, Site Inductions and Site Documents ComplyFlow Help Centre, 27 July 2026; read 6 October 2026
  9. Check Why Your Document Was Rejected and Find the Solution ComplyFlow Help Centre, 13 August 2026; read 6 October 2026
  10. Checking Compliance Status for All Workers (in Bulk) ComplyFlow Help Centre, 9 February 2023; read 6 October 2026

See It Against Your Own Contractors, Sites & Rules.

Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.

Or Speak to Us

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia
Mitchell Bourne

Written by

Mitchell BourneManaging Director, ComplyFlow

Mitchell has run ComplyFlow since 2009 and has spent that time inside the contractor, site, and safety problems of Australian operators. He writes about where compliance actually fails, and what the people responsible for it can do about it.

Writes about: Contractor compliance, WHS duty and proof, Running a compliance program

Questions

Questions People Ask About This.

What are the best KPIs for contractor management?

Start with expiries caught before lapse, the share of active contractors fully approved and overrides with a reason. They are cheap to measure, they show whether the controls are running, and each points to a specific action. Add time to approved, review turnaround and corrective action close-out next, then incident rates once there are enough contractor hours for the rate to mean something.

How do contractor KPIs differ from contract KPIs?

Contractor KPIs measure how the people and companies working on your sites are approved, checked and managed. Contract KPIs measure the agreement itself: time to signature, renewal rate, clause consistency. Search results for 'contractor management KPIs' are mostly the second kind. This guide covers the first.

How many contractor management KPIs should a team track?

Start with 3 to 5 and add more only when the first ones have an owner and a baseline. Ten is a menu, not a mandate: a measure nobody reviews costs time and teaches the team that reports are for show. That number is our judgement, not a published one.

How often should contractor KPIs be reviewed?

Monthly for the leading measures and quarterly for the lagging ones, with a check of the target levels at 90 days. That cadence is our judgement. Lagging measures such as incident rates rest on too few events to read month to month.

What is a good incident rate for contractors?

No published figure is specific to contractors. Safe Work Australia's serious claims frequency rate for 2023-24 (preliminary) was 6.8 per million hours worked across all industries, and it counts claims with at least one week off work. Compare only incidents of that severity, and read it as a reference, not a target.