4 checks UK PMs must run for subcontractor onboarding in construction

Ensure your site remains compliant and audit-ready by following these four essential subcontractor onboarding checks for UK construction projects.

By James Shorter ·

4 checks UK PMs must run for subcontractor onboarding in construction

Supervisor checking subcontractor site access

A compliant onboarding process delivers four things before anyone picks up a tool: verified CIS status, valid employer’s liability insurance on file, site-specific RAMS signed off, and every operative individually inducted. Digital document tracking with expiry alerts is what makes that outcome repeatable across dozens of subbies rather than a one-off scramble. Everything below shows how to build that process and keep it audit-ready.


TL;DR:

  • Verifying CIS status and recording the reference before the first payment are non-negotiable, along with timely collection of employer’s liability and worker evidence.
  • Site-specific RAMS must match the actual construction phase plan, and operative inductions require individual completion before work begins.
  • Continuous oversight through automated expiry alerts and regular spot checks is vital to maintain compliance and support the golden thread of evidence.
  • Only accept a subcontractor on site after all required documents, certificates, and signed attestations are verified and fully logged in an audit-ready register.
  • Using dedicated management software like BRCKS can streamline document tracking, expiry alerts, and audit trail building, reducing manual errors and delays.

Table of Contents

What does a subcontractor onboarding construction checklist actually include?

Subcontractor onboarding in construction runs in a fixed sequence, and skipping steps is where most compliance failures start. The process below takes a subbie from tender award to first day on site without gaps that come back to bite you at audit time.

1. Confirm the appointment. Nothing else starts until the contract or letter of intent is signed and logged. This is your trigger point, not the date they turn up.

2. Verify CIS status. Check the subcontractor’s status with HMRC before the first payment goes anywhere near them, and record the verification result against their file. This determines the deduction rate and it’s non-negotiable.

3. Collect company documents. Employer’s liability, public liability, and professional indemnity where relevant. Note every expiry date the moment the document lands.

4. Collect worker-level evidence. CSCS cards, right-to-work checks, trade qualifications, one document per operative, linked to their name.

5. Require site-specific RAMS. Generic method statements get rejected. RAMS must match your actual construction phase plan, and if they don’t, send them back for revision.

6. Agree the pre-arrival plan. Confirm induction slots and require operatives to register ahead of arrival to prevent gate delays.

7. Set one acceptance condition. Documents complete and verified, or the subbie doesn’t mobilise. No exceptions for “we’ll sort it Monday.”

  • Contract or PO signed and appointment logged
  • CIS verification reference recorded
  • EL/PL/PI certificates on file with expiry dates noted
  • right-to-work and relevant competency evidence per operative
  • Site-specific RAMS approved against the phase plan
  • Induction slot booked and confirmed pre-arrival

Pro Tip: Refuse to release a start date until every box above is ticked. A delayed start is cheaper than an HSE visit that finds an uninducted operative on your scaffold.

What do CIS, CDM 2015 and the Building Safety Act require?

Three separate legal frameworks touch subcontractor onboarding, and treating them as one blob of “compliance paperwork” is how gaps appear.

CIS verification is straightforward on paper: verify the subcontractor’s status with HMRC and retain the verification reference, including their UTR and NINO or CRN, then include the payment correctly on your monthly return. Re-verification is required after a gap in payments, not automatically every job.

CDM 2015 Regulation 8 puts a legal duty on you as the appointing party to take reasonable steps ensuring the subcontractor has the skills, knowledge, experience and organisational capability for the work. That duty is met with evidence, not intention: training records, a health and safety policy, and a track record on comparable work.

The Building Safety Act raises the bar further for higher-risk buildings, pushing duty holders towards a documented, continuously verified competency regime rather than a one-off check at appointment. The phrase you’ll hear repeatedly is the “golden thread”: a continuous record of decisions and evidence that survives staff changes and project handovers.

  • CIS: verification reference, UTR/NINO, monthly return entry
  • CDM 2015: skills, training records, organisational capability evidence
  • Building Safety Act: ongoing verification, not point-in-time sign-off

An inspector or a dispute won’t accept “we checked it once.” They’ll ask for the record, the date, and who signed it off.

How should prequalification evidence competence?

Prequalification exists to filter risk before a subbie ever reaches site, and a scattergun approach here creates rework later. Structure the ask around what you’ll actually need to defend at audit.

Essential company-level documents to request:

  • Health and safety policy, signed and dated
  • SSIP or CHAS accreditation, or equivalent third-party assessment
  • Training matrix showing qualifications held across the workforce
  • Accident and enforcement history for the last three years
  • Basic financial information relevant to contract size

Trade-specific certifications should scale with project risk. A domestic extension doesn’t need the same evidential depth as a hospital refurbishment. Where you can, use the Common Assessment Standard or an equivalent recognised scheme rather than building a bespoke PQQ from scratch. It reduces duplication for subbies working across multiple contractors and speeds up your own review. Whatever you decide, write down the rationale. If a subcontractor is accepted with a caveat, that caveat needs a paper trail.

How do you run site inductions without gate delays?

Every operative needs an individual induction, not a one-per-firm signature on a register nobody reads. Signed evidence per person is what protects you if something goes wrong.

1. Register operatives before travel. Have subbies submit names, CSCS numbers and ID at least 48 hours before mobilisation so mismatches get sorted before anyone’s stood at the gate.

2. Check digitally, not on paper at 7am. Verify CSCS and ID against your records ahead of arrival.

3. Link access to document status. If insurance has lapsed or RAMS aren’t approved, the system should block entry automatically, not rely on a gateman remembering.

4. Check welfare, supervision and plant in the first week, not just the induction pack.

Pro Tip: Gate bottlenecks are almost always a pre-arrival failure, not an induction failure. Fix the registration window and the queue disappears.

How do you track and audit onboarding documents?

An audit-ready register needs specific fields, not a folder of PDFs named “insurance final v3.” Capture policy type, insurer, policy number, expiry date, CIS verification reference, and a unique ID per operative, all linked to the project record.

  • Insurance type, insurer, policy number and expiry date
  • CIS verification reference per subcontractor
  • Operative ID, CSCS number, right-to-work status
  • Date and outcome of last RAMS review

Automated expiry alerts matter more than the register itself. Ongoing monitoring catches the common failure mode: checks are done properly at onboarding, then insurance lapses six months into a long programme and nobody notices until a claim. Blocking site access automatically on expiry, rather than relying on someone remembering to chase, closes that gap. Spreadsheets can hold this data. Workforce portals and construction PM software do it with less manual chasing and a searchable history, which is what supports the golden thread when the Building Safety Act’s evidential standard is tested.

What mistakes cause the most onboarding failures?

The same handful of mistakes recur across most projects, and they’re avoidable with a bit of process discipline.

  • Chasing paperwork at mobilisation instead of before it
  • Accepting generic RAMS that don’t match the phase plan
  • Letting insurance expire mid-project with no alert
  • Starting work before CIS verification is confirmed

When something’s missing, decide fast: pause the affected work, accept a documented and mitigated risk, or allow conditional mobilisation with tighter supervision. Missing or expired documents should pause work until remedied, not get waved through on a promise.

Pro Tip: An expired EL certificate and an unverified CIS status are automatic disqualifiers. Don’t let a good relationship with a subbie override that.

Where does BRCKS fit in the onboarding process?

BRCKS maps directly onto the checklist above rather than replacing your judgement. The subcontractor portal handles document upload and expiry alerts, the photo-led checklists cover RAMS sign-off and induction evidence, and the site diary builds the audit trail automatically as work progresses.

  • Invite subbies free; they upload insurance, CSCS and RAMS through the portal
  • Set expiry alerts so lapsed documents surface before they become a site problem
  • Attach approved RAMS to the mobilisation plan so nobody starts without it
  • Every document and photo files against the right project automatically

It’s a practical way to run the process, not a substitute for knowing what CIS and CDM 2015 actually require.

How should insurance checks and expiry tracking work?

Insurance is the document most likely to lapse quietly, because unlike CIS or RAMS, it rarely gets checked twice. Employer’s liability is a legal minimum for any subcontractor with employees, and most main contractors also require public liability cover, with professional indemnity added where a subbie provides design input, such as a structural steelwork specialist or an M&E contractor doing coordinated drawings.

The check itself is simple: capture the insurer, policy number, cover level and expiry date at onboarding, and verify the certificate is current, not renewed six months ago and forgotten. The failure mode isn’t the initial check, it’s the six months after. A subcontractor onboarded correctly in January can be working uninsured by August if nobody’s watching the renewal date.

Set expiry alerts well before lapse to allow renewal and avoid work stoppage, not on the day itself. That gives the subbie time to renew and gives you time to pause work if they don’t. For long programmes with the same subcontractor across multiple phases, re-check cover levels at each new phase, particularly if the scope or risk profile has changed. A subbie insured for a first-fix package might need higher cover for structural work later in the same job.

Don’t treat insurance as a one-and-done tick box alongside CIS verification. CIS status rarely changes mid-project; insurance does, constantly, and it’s the document most likely to be quietly allowed to expire under time pressure.

What competence evidence do CDM 2015 and the Building Safety Act require?

Competence isn’t a certificate, it’s a demonstrable capability, and the distinction matters when you’re asked to justify a decision after the fact. CDM 2015 Regulation 8 asks whether the subcontractor and its people have the skills, knowledge, experience and organisational capacity for the specific role, not whether they hold a card that says “qualified.”

In practice, evidence that satisfies this duty includes training records tied to named individuals, a track record on comparable projects, membership of a recognised trade body, and a health and safety policy that’s actually been applied, not just written. For organisations, capability also covers whether they have enough competent supervisory staff to manage the work safely, not just enough operatives to do it.

The Building Safety Act tightens this further for higher-risk building work, where the expectation shifts from a point-in-time check to continuous verification through the project lifecycle. That means competence evidence needs a date stamp and a review cycle, not just a file that says “checked” with no indication of when. If a subcontractor’s team changes mid-project, the competence evidence needs updating too, because the duty attaches to the people actually doing the work, not the company name on the contract.

Keep this evidence somewhere retrievable. If HSE or a Building Safety Regulator inspection asks for proof of competence six months after the fact, “we’re confident they were fine” doesn’t hold up. A dated record does.

What competence evidence do CDM 2015 and the Building Safety Act require? — overview diagram

How does prequalification separate PQQ, SSIP and Common Assessment Standard?

These three terms get used interchangeably, and that’s a mistake, because they solve slightly different problems. A PQQ (pre-qualification questionnaire) is your own bespoke set of questions, built around your specific procurement risk. SSIP (Safety Schemes in Procurement) is a family of third-party accreditation schemes, including CHAS, SMAS and Constructionline, that assess a contractor’s health and safety competence once and issue a certificate other buyers can rely on.

PQQ SSIP and Common Assessment Standard comparison

The Common Assessment Standard sits above both: it’s an attempt by the industry to create a single, portable competence assessment that any SSIP member scheme can issue, so a subcontractor doesn’t have to complete a different questionnaire for every main contractor they work with. Accepting Common Assessment Standard certification instead of running your own PQQ from scratch cuts duplication for the subbie and cuts review time for you.

That said, accreditation alone isn’t a substitute for judgement on higher-risk trades. A subcontractor with valid SSIP certification doing routine first-fix carpentry needs less scrutiny than one carrying out temporary works design on a live structure. Scale the depth of your competence evidence to the risk of the specific package, not a blanket policy applied identically across every trade on the job.

Whatever standard you rely on, keep a record of which one, the certificate reference, and its expiry date. Accreditation lapses just like insurance does, and a subcontractor working off an expired SSIP certificate is effectively unverified.

What onboarding mistakes cost the most time to fix?

The mistakes that cause real damage aren’t the obvious ones, they’re the ones that look fine until a project’s six weeks in. Chasing insurance certificates after a subbie has already started work is the most common, because it inverts the entire point of verification: the check exists to prevent risk, not to document it after exposure has already happened.

A close second is accepting RAMS that were clearly written for a different job and lightly edited. Generic method statements that don’t reference your actual site conditions, access routes or adjacent trades won’t hold up if there’s an incident, and they signal a subcontractor who isn’t engaging with the specific risks of your project.

Letting document expiry slide during long programmes causes more compliance gaps than any onboarding failure, because attention naturally shifts to the work once mobilisation is done. This is precisely why expiry tracking needs to be automated rather than manual. A spreadsheet with expiry dates in a column only works if someone actually opens it every week.

Unverified CIS status is a mistake with a direct financial consequence: pay a subcontractor without verification and you risk applying the wrong deduction rate, which becomes your problem with HMRC, not theirs. The mitigation for all four of these is the same: build the check into the workflow so it happens before the risk is created, not as a retrospective fix once something’s already gone wrong.

What’s the onboarding timeline from contract award to site start?

The gap between signing a subcontractor and them turning up on site is where most compliance failures either get caught or get missed, depending on how that window is used.

Day 0: Contract award. Log the appointment and issue your document request immediately, not the week before mobilisation.

Days 1 to 5: Document submission. The subcontractor submits company-level evidence, insurance certificates and worker-level documents.

Days 3 to 7: Verification. Run CIS verification, check insurance validity, and review RAMS against your construction phase plan in parallel rather than sequentially.

Days 5 to 10: Revision cycle. Where RAMS or documents fall short, send them back with specific feedback and a resubmission deadline.

48 hours before mobilisation: Pre-arrival registration. Operatives register their details, CSCS numbers and ID for pre-checking, closing off the most common cause of gate delays.

Day of mobilisation: Induction. Each operative completes an individual, signed induction before touching any tools.

This entire window should run in parallel with your own site preparation, not sequentially after it. A subcontractor confirmed weeks in advance but only asked for documents two days before start is the single biggest driver of onboarding delays on otherwise well-planned projects.

What forms and signatures does subcontractor acceptance require?

Acceptance isn’t one signature, it’s a set of them, each covering a distinct piece of risk. Missing any one leaves a gap that surfaces at the worst possible time, usually during a dispute or an incident investigation.

  • Signed subcontract or works order confirming scope, price and programme
  • CIS verification confirmation recorded against the subcontractor’s file
  • Insurance certificates for EL, PL and PI where relevant, with expiry dates logged
  • Site-specific RAMS, signed off as reviewed and approved against the phase plan
  • Individual induction record signed by each operative, not one signature per firm
  • Confirmation of right-to-work checks for every worker on site

Treat this as a single acceptance gate rather than a series of independent approvals scattered across email threads. If any one item is outstanding, the subcontractor doesn’t mobilise. That sounds harsh until the first time a missing signature becomes the reason a claim gets contested.

Who is responsible for what during onboarding?

Onboarding fails most often when both parties assume the other is handling a specific step. Splitting responsibility clearly at the start avoids that.

The main contractor owns CIS verification, sets the RAMS review standard against the construction phase plan, runs site inductions, and maintains the document register with expiry tracking. Ultimately, the main contractor carries the CDM 2015 duty to check competence before appointment, which means the verification step can’t be delegated away even if a subcontractor insists their paperwork is “all sorted.”

The subcontractor owns producing accurate, site-specific RAMS rather than recycled templates, keeping insurance current and providing renewal evidence proactively, submitting worker-level documents (CSCS, right-to-work, trade qualifications) ahead of the registration deadline, and briefing their own operatives on site-specific hazards before arrival, not relying solely on the main contractor’s induction to cover it.

Both parties share responsibility for flagging changes: if the subcontractor’s team composition shifts mid-project, or if the main contractor changes the scope in a way that affects risk, that change needs to trigger a fresh look at competence and RAMS, not silence until something goes wrong. A clear written split of who does what, agreed at appointment, prevents the classic argument after an incident where each side believed the other was checking something nobody actually checked.

How do you monitor compliance after onboarding is complete?

Onboarding isn’t a one-off gate, it’s the start of a monitoring cycle that has to run for the life of the contract. The most common compliance failure isn’t a bad initial check, it’s a good initial check that nobody revisits.

Set a monitoring cadence appropriate to project length: monthly spot checks on long programmes, tied to key milestones on shorter ones. Spot checks should cover whether insurance is still valid, whether the RAMS in use on site still match what was approved, and whether the operatives on site match the register of inducted, verified individuals.

Automated expiry alerts do the bulk of this work without manual chasing, flagging insurance and accreditation renewals before they lapse rather than after. But automation doesn’t replace a physical or documented check that RAMS in practice match RAMS on paper, because a subcontractor can hold valid paperwork while working in a way that’s drifted from what was actually approved.

Audit trails matter here as much as the checks themselves. If a dispute arises over a variation, an incident, or a payment withheld for non-compliance, the record of when something was checked, by whom, and what the outcome was is what resolves it quickly. Without that trail, disputes drag on because neither side can point to a clear, dated fact.

What training do subcontractors need beyond site induction?

Site induction covers the specific hazards of your project, but it isn’t a substitute for the ongoing competence training that CDM 2015 expects subcontractors to maintain independently. Distinguish clearly between the two, because conflating them is a common gap.

Beyond induction, expect and verify: CSCS card currency (most cards require periodic renewal tied to ongoing training), trade-specific certifications relevant to the scope (asbestos awareness, working at height, confined spaces, depending on the work), first aid and fire marshal cover appropriate to crew size, and any plant or equipment-specific competence, such as a valid ticket for the machinery they’re operating on your site.

For higher-risk trades, ask when refresher training was last completed, not just whether a card is technically valid. A CSCS card can remain in date while the underlying training it represents is several years old, and the gap between “technically qualified” and “currently competent” is exactly where CDM 2015’s organisational capability duty bites.

Document this training evidence in the same register as your other onboarding documents, with the same expiry tracking discipline. Training records that lapse mid-project without anyone noticing create the same exposure as an expired insurance certificate, just less visible until something goes wrong.

A builder’s honest priority list for onboarding

If time is short, verify CIS and check employer’s liability insurance first. Everything else can be finished in parallel, but those two protect you legally and financially from day one. On short domestic jobs, a lighter PQQ is fine. On long programmes, RAMS quality and ongoing insurance checks matter more than the initial paperwork. My one tip from years of watching this go wrong: chase documents before mobilisation, never during it.

— James

Get BRCKS running on your next subcontractor package

BRCKS is the practical alternative to running onboarding through spreadsheets and email threads. It gives you one place to hold verification references, insurance expiry dates, RAMS sign off and induction records, so nothing gets missed when three subbies start on the same Monday.

BRCKS

Start with the construction project management software built around this exact workflow, invite your subcontractors in free, and let them upload their own documents before they arrive on site. Import your existing checklist, set expiry alerts on insurance and accreditation, and let the subcontractor management tools flag anything outstanding before mobilisation day, not after. With subscription pricing per seat billed annually for your core team and subcontractors and clients free, it replaces the scramble with a record you can actually stand behind at audit. Check pricing and start a free trial to see it against your next package.

Sources

Financial failure mid-project causes as much disruption as a safety failure, and it’s checked far less rigorously. A basic financial review at prequalification stage should include recent accounts or a credit reference check appropriate to contract value, confirmation of adequate working capital for the scope being awarded, and a check for any recent County Court judgements or insolvency proceedings.

References carry more weight than the financial figures alone. Speak directly to two or three previous clients or main contractors the subcontractor has worked for, and ask specific questions: did they deliver to programme, how did they handle variations, and how did they respond when something went wrong on site. A subcontractor with strong accounts but a pattern of contract disputes is a bigger risk than one with modest turnover and a clean delivery record.

Scale the depth of this check to contract value and project duration. A £15,000 package over three weeks doesn’t need the same financial scrutiny as a £400,000 package running eighteen months, where a subcontractor’s cash flow problems six months in could stall the whole programme. For long-duration contracts, consider a light-touch financial recheck at major milestones rather than relying entirely on the pre-award snapshot, since financial position can shift significantly over a year or more.

Record the outcome of this check alongside your other prequalification evidence, even if the conclusion is simply “acceptable for contract value.” That record is what shows you exercised reasonable due diligence if a subcontractor does fail mid-project.

FAQ

Do subcontractors need to register for CIS?

Yes, if they carry out construction work for a contractor. Registration affects the deduction rate, and the contractor must still verify their status with HMRC before the first payment regardless of registration status.

What are the three types of subcontractors?

They’re generally categorised as labour-only subcontractors, supply-and-fix subcontractors who provide both materials and labour, and specialist trade subcontractors carrying out design or technically complex packages such as M&E.

What employment rights do subcontractors have?

Genuinely self-employed subcontractors don’t have employee rights like paid holiday or unfair dismissal protection, but they retain rights around health and safety, payment terms, and protection from discrimination regardless of employment status.

Who is responsible for a subcontractor’s actions on site?

The main contractor carries the CDM 2015 duty to check competence before appointment and to manage health and safety on site, while the subcontractor is responsible for its own workers’ conduct, training and compliance with the agreed RAMS.

Can onboarding software like BRCKS replace legal compliance checks?

No single tool replaces the legal checks themselves, but a system like BRCKS makes it far easier to verify, store and track the evidence CIS, CDM 2015 and the Building Safety Act actually require, with expiry alerts that stop checks lapsing unnoticed.

Recommended


How BRCKS Can Help

Managing these essential subcontractor checks manually can be a significant administrative burden, but BRCKS simplifies the entire onboarding process by centralising compliance data and documentation. Our platform ensures that nothing slips through the cracks, allowing project managers to focus on delivery rather than chasing paperwork. By integrating these checks into your digital workflow, you can build a more resilient and compliant supply chain with ease. We invite you to explore how BRCKS can transform your site management and streamline your subcontractor relationships today. Learn more at BRCKS and explore our full feature set.


Sources