Service
Your regulatory exposure does not end where outsourced work begins.
Contractors, specialist vendors and external consultants may perform important work at an industrial facility, but engaging a third party does not automatically transfer every statutory responsibility connected with that work. The establishment must understand what the third party is authorised to do, which duties remain with the establishment and what evidence demonstrates that the activity is being performed compliantly.
AequiRadix examines third-party engagements from a regulatory perspective. The review connects each outsourced activity with the applicable legislation, facility approvals, statutory competence requirements, operating controls and documentary evidence.
Where exposure arises
Contractors
Contractors may deploy labour, undertake construction or installation, maintain machinery, perform electrical work or participate directly in industrial operations. The regulatory position depends on the nature of the work, the number and category of persons deployed, where the work is performed and whether the activity falls within the facility's core or ancillary operations. The Occupational Safety, Health and Working Conditions Code has been in force since 21 November 2025 and contains specific provisions for contract labour, contractor licensing, principal-employer responsibilities and workplace safety. The applicable registration, licensing, forms and authority procedure in Tamil Nadu should nevertheless be confirmed against the current Central-State transitional position rather than inferred from superseded forms or older administrative material.
Vendors and service providers
Waste transporters, treatment and disposal facilities, electrical-service providers, fire-equipment vendors and treatment-plant operators may require particular authorisations, competence or operating controls. Their work can also affect the establishment's own consent conditions, safety obligations and statutory records. Verification must therefore extend beyond a vendor's general business credentials. The scope, validity and legal relevance of the document relied upon must correspond to the activity actually performed.
Consultants
Consultants may prepare consent applications, statutory returns, technical reports, drawings or compliance records. Their involvement does not eliminate the need for the establishment to verify the underlying information, confirm the consultant's authority and ensure that an appropriately authorised person approves or submits the document. The applicable obligations differ with the engagement. Some arise directly under legislation, others from a facility's licence or consent conditions, while additional controls may be imposed contractually to allocate tasks and evidence requirements. A contractual indemnity may allocate commercial consequences between the parties, but it does not necessarily displace a statutory duty imposed on the establishment, employer, occupier, principal employer, sender or owner.
For prioritising facility-wide regulatory exposure, see Regulatory Risk. For responding when an authority has already issued a communication, see Notice & Enforcement Response. This page focuses on exposure that arises from contractors, vendors and consultants.
Illustrative facility
External parties at a Tamil Nadu manufacturing facility
Illustrative scenario, not an assessment of an actual establishment or third party.
The example concerns an operating precision-engineering and electric-vehicle components facility in Tamil Nadu. Its activities include CNC machining, aqueous surface preparation, powder coating and mechanical assembly.
The facility engages:
- A housekeeping and manpower contractor
- A machinery-installation and maintenance contractor
- An electrical-maintenance service provider
- A hazardous-waste transporter and disposal service provider
- A contractor operating its effluent-treatment system
- A fire-equipment inspection and maintenance vendor
- A regulatory or technical consultant preparing statutory documentation
Management wants to identify which authorisations and qualifications must be verified, which responsibilities remain with the facility, what evidence should be retained and which deficiencies or changes require escalation.
| Scenario factor | Illustrative assumption |
|---|---|
| Facility | Operating precision-engineering and electric-vehicle components facility in Tamil Nadu; CNC machining, aqueous surface preparation, powder coating and mechanical assembly |
| Third-party engagements | Housekeeping and manpower, machinery installation and maintenance, electrical maintenance, hazardous-waste transport and disposal, effluent-treatment operation, fire-equipment servicing, and a regulatory or technical consultant |
| Management question | Which authorisations and qualifications must be verified, which responsibilities remain with the facility, what evidence should be retained, and which deficiencies or changes require escalation |
Exposure and control register
The sample register illustrates how each outsourced activity is connected to the applicable responsibility, evidence and operating control. It does not assume that every listed requirement applies to every engagement.
| Third-party activity | Potential regulatory exposure | Responsibility or authority | Verification and evidence | Monitoring or corrective action |
|---|---|---|---|---|
| Housekeeping and manpower services | The engagement may attract contract-labour, wage, working-condition and social-security requirements depending on the legal relationship, work performed, deployment and applicable coverage provisions. | Contractor and establishment or principal employer, according to the applicable provision; labour authorities, EPFO and ESIC as relevant. | Verify the contract scope, worker list, deployment location, current registration or licence where applicable, wage and attendance records, worker identification and coverage particulars. Do not demand a contractor licence mechanically without first confirming applicability and the current procedural route. | Reconcile persons entering the facility with contractor records. Escalate undeclared deployment, changes in worker strength or work scope, expired documents and inconsistencies between attendance, wages and statutory records. |
| EPF and ESI relating to deployed personnel | A contractor's registration number or payment challan alone may not show that contributions relating to the personnel deployed at the facility were correctly reported. | Contractor and principal employer or establishment responsibilities depend on the applicable social-security provisions and engagement facts. EPFO and ESIC administer the respective schemes. | Verify applicable coverage, deployed-worker particulars, UAN or insurance information where relevant, wage-period records, electronic returns and remittance evidence. EPFO provides a principal-employer facility for recording contractors and monitoring worker-level contractor remittances. EPFO principal-employer facility | Reconcile monthly deployment and wage information against contribution records where applicable. Investigate omitted workers, unmatched identities, unexplained wage differences or remittances unrelated to the deployment period. |
| Machinery installation and maintenance | Contractor work may introduce risks involving isolation, lifting, hot work, work at height, confined spaces, guarding or modification of an approved machinery layout. It may also affect factory-plan or consent particulars. | The contractor controls its work execution, while the establishment retains duties relating to its workplace, approved configuration and site coordination. DISH or another technical authority may become relevant depending on the work. | Review method statements, risk assessments, worker competence, lifting or testing records, equipment certificates where applicable, insurance, supervision arrangements and the approved scope of work. | Use activity-specific work permits and isolation controls. Stop work where site conditions, personnel or equipment differ materially from the approved method. Route physical or process modifications through regulatory change control before implementation. |
| Electrical operation and maintenance | Electrical work performed by an unqualified or undesignated person, or outside the authorised scope, can create statutory and safety exposure even if a service contract exists. | Consumer or owner of the installation, electrical contractor and designated personnel; Electrical Inspectorate or supply authority where applicable. | Verify the service provider's current licence or approval, the competence or work permit of the persons deployed, designation records, test instruments, test reports and the exact voltage and installation scope. The CEA Safety Regulations require appropriately competent designated persons for work on electrical lines and apparatus. CEA Safety Regulations 2023 | Maintain a current list of authorised persons and permitted work. Reassess before changes to transformers, switchgear, generators, sanctioned load or previously approved installations. Preserve isolation, testing and restoration records. |
| Hazardous-waste transport | Improper packaging, labelling, transport authorisation, manifest handling or emergency information may expose the waste generator even when transportation is outsourced. | Waste sender or occupier, transporter and receiver under the Hazardous and Other Wastes Rules; TNPCB and other affected State Pollution Control Boards as applicable. | Verify the parties' relevant authorisations, vehicle and transporter particulars, waste description, packaging, labels, emergency information and Form 10 manifest. The Rules allocate safe-transport responsibility to the authorised sender or receiver arranging the transport and require that responsibility to be identified in the manifest. HOW Rules 2016 | Reconcile every dispatch with the manifest and receiver's acknowledgement. Escalate route or receiver changes, vehicle substitution, missing manifest copies, quantity discrepancies, accidents or delivery to a facility outside the approved route. |
| Waste treatment, recycling or disposal | Delivery to an unsuitable, expired or unauthorised receiver may be inconsistent with the facility's authorisation and waste-management duties. A transporter's documents do not establish that the destination is authorised for the particular waste. | Waste generator or occupier and receiving actual user, recycler or treatment, storage and disposal facility; TNPCB or the relevant Pollution Control Board. | Verify the receiver's authorisation, validity, waste categories and permitted activity. Retain manifests, weighment records, invoices and certificates evidencing receipt, recycling, utilisation or disposal. | Periodically confirm authorisation status and reconcile dispatched quantities against received quantities and facility records. Suspend dispatch where scope, validity or destination cannot be established. |
| Effluent-treatment operation | Outsourcing treatment-plant operation does not by itself alter the industry's consent conditions. Poor operation, bypass, inadequate dosing, missing records or untreated discharge may affect the facility's regulatory position. | The consent holder remains responsible for compliance with its consent; the contractor performs the assigned operating tasks. TNPCB monitors treatment systems and compliance with consented discharge arrangements. | Define operating parameters, staffing competence, sampling, chemical use, maintenance, breakdown reporting and record requirements. Retain logs, laboratory reports, meter records, sludge records and corrective-action evidence. TNPCB Policy Note 2025-2026 | Review operational data rather than relying only on the contractor's invoice or attendance. Escalate abnormal results, bypasses, equipment failures, monitoring exceedances and departures from the approved treatment or disposal arrangement. |
| Fire-equipment inspection and maintenance | Service labels or certificates do not establish that the complete fire-protection arrangement remains adequate, functional or consistent with the approved fire plan. | Building occupier or establishment and the service provider; Tamil Nadu Fire and Rescue Services administers fire-safety inspections, NOCs and fire licences where applicable. | Verify the vendor's scope and competence, equipment inventory, service reports, test results, replaced components, defect list and closure evidence. Compare serviced systems against the approved fire plan and facility changes. TNFRS Fire Safety | Track unresolved defects and equipment taken out of service. Reassess after layout, occupancy, storage, utility or fire-load changes. Maintain access, exits and emergency arrangements independently of vendor servicing. |
| Regulatory and technical consultant | Applications, returns, plans or technical statements may contain incorrect, unsupported or outdated information. External preparation does not by itself establish authority to sign or submit on behalf of the establishment. | The establishment, authorised signatory and consultant according to the particular filing and professional scope; relevant statutory authority. | Define the assignment, source documents, assumptions, preparer, reviewer and authorised signatory. Retain the filed version, annexures, acknowledgement, portal communications and evidence supporting each material declaration. | Require factual verification before submission. Escalate unexplained changes, unsupported declarations, use of outdated approvals, filings made without authority and departmental communications not promptly shared with the establishment. |
| Expiry, incident or scope change | A previously acceptable third party may cease to satisfy requirements because its authorisation expires, personnel change, subcontracting occurs, an incident happens or the work expands beyond the verified scope. | Responsibility depends on the activity and governing law; the establishment should maintain change and escalation controls for work conducted at or for its facility. | Maintain a controlled record of authorisations, competence documents, work scope, deployment, validity, incidents and subcontractors. Documentary verification should be connected to the actual activity and personnel. | Trigger reassessment before renewal, expansion, substitution, subcontracting or introduction of new materials, equipment or work methods. Record deficiencies, corrective actions, responsible persons and closure evidence. |
Housekeeping and manpower services
- Potential regulatory exposure
- The engagement may attract contract-labour, wage, working-condition and social-security requirements depending on the legal relationship, work performed, deployment and applicable coverage provisions.
- Responsibility or authority
- Contractor and establishment or principal employer, according to the applicable provision; labour authorities, EPFO and ESIC as relevant.
- Verification and evidence
Verify the contract scope, worker list, deployment location, current registration or licence where applicable, wage and attendance records, worker identification and coverage particulars. Do not demand a contractor licence mechanically without first confirming applicability and the current procedural route.
- Monitoring or corrective action
Reconcile persons entering the facility with contractor records. Escalate undeclared deployment, changes in worker strength or work scope, expired documents and inconsistencies between attendance, wages and statutory records.
EPF and ESI relating to deployed personnel
- Potential regulatory exposure
- A contractor's registration number or payment challan alone may not show that contributions relating to the personnel deployed at the facility were correctly reported.
- Responsibility or authority
- Contractor and principal employer or establishment responsibilities depend on the applicable social-security provisions and engagement facts. EPFO and ESIC administer the respective schemes.
- Verification and evidence
Verify applicable coverage, deployed-worker particulars, UAN or insurance information where relevant, wage-period records, electronic returns and remittance evidence. EPFO provides a principal-employer facility for recording contractors and monitoring worker-level contractor remittances.
EPFO principal-employer facility- Monitoring or corrective action
Reconcile monthly deployment and wage information against contribution records where applicable. Investigate omitted workers, unmatched identities, unexplained wage differences or remittances unrelated to the deployment period.
Machinery installation and maintenance
- Potential regulatory exposure
- Contractor work may introduce risks involving isolation, lifting, hot work, work at height, confined spaces, guarding or modification of an approved machinery layout. It may also affect factory-plan or consent particulars.
- Responsibility or authority
- The contractor controls its work execution, while the establishment retains duties relating to its workplace, approved configuration and site coordination. DISH or another technical authority may become relevant depending on the work.
- Verification and evidence
Review method statements, risk assessments, worker competence, lifting or testing records, equipment certificates where applicable, insurance, supervision arrangements and the approved scope of work.
- Monitoring or corrective action
Use activity-specific work permits and isolation controls. Stop work where site conditions, personnel or equipment differ materially from the approved method. Route physical or process modifications through regulatory change control before implementation.
Electrical operation and maintenance
- Potential regulatory exposure
- Electrical work performed by an unqualified or undesignated person, or outside the authorised scope, can create statutory and safety exposure even if a service contract exists.
- Responsibility or authority
- Consumer or owner of the installation, electrical contractor and designated personnel; Electrical Inspectorate or supply authority where applicable.
- Verification and evidence
Verify the service provider's current licence or approval, the competence or work permit of the persons deployed, designation records, test instruments, test reports and the exact voltage and installation scope. The CEA Safety Regulations require appropriately competent designated persons for work on electrical lines and apparatus.
CEA Safety Regulations 2023- Monitoring or corrective action
Maintain a current list of authorised persons and permitted work. Reassess before changes to transformers, switchgear, generators, sanctioned load or previously approved installations. Preserve isolation, testing and restoration records.
Hazardous-waste transport
- Potential regulatory exposure
- Improper packaging, labelling, transport authorisation, manifest handling or emergency information may expose the waste generator even when transportation is outsourced.
- Responsibility or authority
- Waste sender or occupier, transporter and receiver under the Hazardous and Other Wastes Rules; TNPCB and other affected State Pollution Control Boards as applicable.
- Verification and evidence
Verify the parties' relevant authorisations, vehicle and transporter particulars, waste description, packaging, labels, emergency information and Form 10 manifest. The Rules allocate safe-transport responsibility to the authorised sender or receiver arranging the transport and require that responsibility to be identified in the manifest.
HOW Rules 2016- Monitoring or corrective action
Reconcile every dispatch with the manifest and receiver's acknowledgement. Escalate route or receiver changes, vehicle substitution, missing manifest copies, quantity discrepancies, accidents or delivery to a facility outside the approved route.
Waste treatment, recycling or disposal
- Potential regulatory exposure
- Delivery to an unsuitable, expired or unauthorised receiver may be inconsistent with the facility's authorisation and waste-management duties. A transporter's documents do not establish that the destination is authorised for the particular waste.
- Responsibility or authority
- Waste generator or occupier and receiving actual user, recycler or treatment, storage and disposal facility; TNPCB or the relevant Pollution Control Board.
- Verification and evidence
Verify the receiver's authorisation, validity, waste categories and permitted activity. Retain manifests, weighment records, invoices and certificates evidencing receipt, recycling, utilisation or disposal.
- Monitoring or corrective action
Periodically confirm authorisation status and reconcile dispatched quantities against received quantities and facility records. Suspend dispatch where scope, validity or destination cannot be established.
Effluent-treatment operation
- Potential regulatory exposure
- Outsourcing treatment-plant operation does not by itself alter the industry's consent conditions. Poor operation, bypass, inadequate dosing, missing records or untreated discharge may affect the facility's regulatory position.
- Responsibility or authority
- The consent holder remains responsible for compliance with its consent; the contractor performs the assigned operating tasks. TNPCB monitors treatment systems and compliance with consented discharge arrangements.
- Verification and evidence
Define operating parameters, staffing competence, sampling, chemical use, maintenance, breakdown reporting and record requirements. Retain logs, laboratory reports, meter records, sludge records and corrective-action evidence.
TNPCB Policy Note 2025-2026- Monitoring or corrective action
Review operational data rather than relying only on the contractor's invoice or attendance. Escalate abnormal results, bypasses, equipment failures, monitoring exceedances and departures from the approved treatment or disposal arrangement.
Fire-equipment inspection and maintenance
- Potential regulatory exposure
- Service labels or certificates do not establish that the complete fire-protection arrangement remains adequate, functional or consistent with the approved fire plan.
- Responsibility or authority
- Building occupier or establishment and the service provider; Tamil Nadu Fire and Rescue Services administers fire-safety inspections, NOCs and fire licences where applicable.
- Verification and evidence
Verify the vendor's scope and competence, equipment inventory, service reports, test results, replaced components, defect list and closure evidence. Compare serviced systems against the approved fire plan and facility changes.
TNFRS Fire Safety- Monitoring or corrective action
Track unresolved defects and equipment taken out of service. Reassess after layout, occupancy, storage, utility or fire-load changes. Maintain access, exits and emergency arrangements independently of vendor servicing.
Regulatory and technical consultant
- Potential regulatory exposure
- Applications, returns, plans or technical statements may contain incorrect, unsupported or outdated information. External preparation does not by itself establish authority to sign or submit on behalf of the establishment.
- Responsibility or authority
- The establishment, authorised signatory and consultant according to the particular filing and professional scope; relevant statutory authority.
- Verification and evidence
Define the assignment, source documents, assumptions, preparer, reviewer and authorised signatory. Retain the filed version, annexures, acknowledgement, portal communications and evidence supporting each material declaration.
- Monitoring or corrective action
Require factual verification before submission. Escalate unexplained changes, unsupported declarations, use of outdated approvals, filings made without authority and departmental communications not promptly shared with the establishment.
Expiry, incident or scope change
- Potential regulatory exposure
- A previously acceptable third party may cease to satisfy requirements because its authorisation expires, personnel change, subcontracting occurs, an incident happens or the work expands beyond the verified scope.
- Responsibility or authority
- Responsibility depends on the activity and governing law; the establishment should maintain change and escalation controls for work conducted at or for its facility.
- Verification and evidence
Maintain a controlled record of authorisations, competence documents, work scope, deployment, validity, incidents and subcontractors. Documentary verification should be connected to the actual activity and personnel.
- Monitoring or corrective action
Trigger reassessment before renewal, expansion, substitution, subcontracting or introduction of new materials, equipment or work methods. Record deficiencies, corrective actions, responsible persons and closure evidence.
A document check is only one part of third-party oversight. A valid certificate may confirm that a contractor or vendor holds a particular authorisation; it does not prove that every person, vehicle, waste stream, installation or site activity falls within its scope or is being managed compliantly.
The register should distinguish:
- Verified requirement: The obligation and supporting evidence are established.
- Potential exposure: Available facts indicate that a requirement may apply, but further verification is needed.
- Identified deficiency: The required authorisation, evidence or operating control is missing, expired, inconsistent or not being followed.
- Contractual control: The requirement arises from the engagement terms rather than directly from legislation.
- Not presently applicable: Sufficient facts indicate that the requirement is not attracted by the reviewed activity.
How risk is managed
- Identify third parties
- Classify regulated activities
- Determine statutory responsibilities
- Verify authorisations and records
- Establish site controls
- Monitor relevant obligations
- Correct deficiencies
- Reassess changes
Identify and classify
Record every contractor, vendor and consultant performing work that may affect labour, safety, environmental, waste, fire, electrical or approval compliance. Classify the actual activity rather than relying on the supplier's commercial description.
Allocate responsibility
Determine which duties fall on the third party, which remain with the establishment and which require coordinated action. Contractual terms should support this allocation without assuming that legislation permits the establishment to transfer its statutory role.
Verify and control
Check the scope, validity and relevance of the required documents, then establish site-access, work-authorisation, supervision, reporting and evidence controls appropriate to the activity.
Monitor and reassess
Record deficiencies and corrective actions. Reassess the engagement when the work, deployment, personnel, subcontractors, materials, equipment, authorisations or facility conditions change.
What the client receives
AequiRadix may provide:
- A third-party activity and regulatory-exposure register
- Identification of applicable statutory and approval-based responsibilities
- Contractor, vendor and consultant verification requirements
- A documentary and operational evidence checklist
- Responsibility allocation between the establishment and third party
- Monitoring and periodic-review requirements
- Identification of missing, expired or inconsistent authorisations
- Recommended corrective and preventive actions
- Escalation criteria for incidents, deficiencies and unresolved matters
- Change-control triggers for altered activities, deployment or engagement scope
The deliverable is designed for use by management, EHS, HR, engineering, procurement and facility teams. It establishes a common view of what must be verified before engagement, what must be controlled during the work and what evidence should remain after completion.
Know the regulatory exposure behind every outsourced activity.
Share the nature of the facility's operations and the contractors, vendors and consultants engaged. AequiRadix will review the available information and recommend the appropriate scope for a third-party regulatory-risk assessment.
Review Third-Party Compliance ExposureThe applicable responsibilities depend on the nature of the work, legal relationship, deployment, regulatory coverage, facility approvals and current Central and Tamil Nadu procedures.
Enquiry · Third-Party Risk
Where does your third-party compliance concern arise?
A brief outline is enough to begin. We will review your enquiry and get in touch to understand the requirement.
Source references
- Occupational Safety, Health and Working Conditions Code, 2020, including employer, contract-labour, contractor and principal-employer provisions
- OSH Code Commencement Notification, S.O. 5321(E), 21 November 2025, Ministry of Labour and Employment
- Occupational Safety, Health and Working Conditions (Central) Rules, 2025, applicable within their prescribed jurisdiction and framework
- Ministry of Labour FAQs on the Labour Codes, including transitional guidance on existing rules
- Tamil Nadu Labour Department, including the published draft Occupational Safety, Health and Working Conditions rules
- Directorate of Industrial Safety and Health, Tamil Nadu, the State enforcement portal for factories and construction safety
- EPFO Principal Employer facility, for recording contractors and contract-worker information
- EPFO Circular on Monitoring Contractor Compliance, including contractor declaration and remittance-verification controls
- Code on Social Security, 2020, including social-security coverage and contractor-related provisions
- Hazardous and Other Wastes (Management and Transboundary Movement) Rules, 2016, particularly transportation, authorisation and manifest requirements
- Hazardous-waste Manifest, Form 10, Tamil Nadu Pollution Control Board
- TNPCB Policy Note 2025-2026, including consent administration and monitoring of treatment systems
- Central Electricity Authority (Measures Relating to Safety and Electric Supply) Regulations, 2023, including designated-person and competence requirements
- Tamil Nadu Fire and Rescue Services, Fire Safety, including inspections, NOCs and fire licences
Sources verified: 3 October 2026.