
Say a new contractor starts on Monday. By mid-morning she has a laptop, a building pass, and access to the same systems your permanent staff use every day. So here’s a question worth considering: who screened her?
If the honest answer is “the recruitment agency, we assume”, you’ve found the gap this article is about. In most contractor arrangements, the client assumes the agency ran the checks. The agency ran whatever its own contracts required, which may be thorough or may be a CV skim. Nobody necessarily compares the two. The contractor did everything asked of her, the process just didn’t ask for much.
The good news is that the differences between screening contractors and permanent staff are structural, and structural problems have structural fixes. This guide maps what actually changes and how to build one screening standard that covers everyone who works for you, whatever their contract says.
In this guide:
The differences are typically less than most policies assume, and more than most processes handle. The checks themselves barely change: identity, right to work, criminal history, qualifications, and references are just as relevant for a six-month contractor as for a permanent hire, because risk follows the role, whatever the employment type. A contractor with admin rights to your finance system carries the same risk profile as the employee sitting next to them.
What changes is everything around the checks. Four differences are key.
Accountability is split. A permanent hire has one employer, one HR team, and one screening decision. A contractor might sit behind a recruitment agency, a labour hire firm, or their own company, and every extra party is another place where “someone else handled it” can take root.
Speed does the skipping. Contractors are usually brought in because something is urgent. A permanent hire can wait a week for checks to clear. A contractor is often expected on site within days, and screening is the step that usually gets waived to hit the start date.
Contractors churn, and they come back. Permanent staff are screened once and stay. Contractors finish, disappear for a year, and return through a different manager or a different agency, carrying the same “already screened” label that was true eighteen months ago.
The credential can expire before the contract does. A visa, licence, or certification that was valid at day one has no obligation to stay valid until day 180. Longer engagements outlive their paperwork more often than anyone expects.
None of these gaps is about contractors being riskier people. They’re about contractor arrangements giving risk more places to “hide,” and that’s a process problem you can fix.
Ask that question about any contractor in your organisation and watch how long the answer takes. The delay is the false assumption gap, and it’s where most contractor screening failures occur.
Here’s how it forms. When a contractor comes through an agency, the screening that happens is the agency’s screening: run to the agency’s standard, by the agency’s chosen provider, against the agency’s definition of “cleared.” That might align with your policy, but it might also mean an identity check and nothing else. Unless your contract says otherwise, you don’t get to decide, and you often don’t get to see.
The agencies aren’t the bad guys here. Good labour hire firms are often contractually obligated to prove compliance on behalf of multiple end clients at once, and many run rigorous processes. The failure is in the handover. The client never states a standard, the agency applies its default, and then both sides file the contractor under “done.”
Genuine reliance on agency screening looks different. It means the screening standard is written into the agency agreement, check by check. It means evidence of completion arrives before the contractor does. And it means audit rights, so you can confirm the process is being followed rather than taking it on faith. If your agency agreements don’t currently say who screens, for what, and to whose standard, that’s the first fix on the list.
More than most screening policies assume, and the detail shifts depending on where you operate, which is exactly how multi-country employers get caught out.
Australia. Work-rights obligations under the Migration Act extend past direct employees to contractors, labour hire, and agency staff. Penalties apply per worker whether or not the employer knew, and new criminal offences for exploiting a worker’s visa status have been in force since July 2024.
United Kingdom. Statutory right to work checks apply to the people you employ, while Home Office guidance strongly encourages employers to confirm their contractors and labour providers are running checks of their own, or to do the checking themselves.
United States. Form I-9 requirements attach to employees rather than independent contractors, although knowingly using unauthorised contract labour remains unlawful, and E-Verify is mandatory for federal contractors.
New Zealand. The Immigration Act 2009 puts the onus on the employer to verify work entitlement, and labour-hire arrangements can still carry verification obligations.
The pattern underneath the variation is more useful than any single rule. Regulators care about who is doing the work, and they’re steadily less interested in what the contract calls that person. Australia’s new aged care regime is a current example. Its worker screening obligations explicitly reach workers engaged through subcontractors, associated providers, and digital platforms, and NDIS worker screening operates the same way. When a regulator writes “worker,” the safest reading is “everyone,” and pre-employment screening that only triggers for permanent hires is a policy built for a workforce that no longer really exists.
Pre-employment screening answers exactly one question: was this person compliant on day one? For a permanent employee, that answer starts aging immediately. For a contractor, it ages faster, because contract work multiplies the moments where compliance can break.
Visas expire mid-engagement, and licences lapse between contracts. Working rights can change with nobody obliged to tell you. A contractor cleared in March can be non-compliant by September while the engagement rolls on, and the twelve-month contract that outlives its own paperwork is common enough to plan for rather than discover.
Then there’s the return trip. A contractor who finishes in June and comes back the following August usually walks in again on the strength of their old file. Nothing about the intervening year (a new visa condition, a lapsed certification, a licence that wasn’t renewed) is visible to the manager who re-engages them, because nobody is looking.
Businesses tend to discover all of this in the worst available way, which is when a client, insurer, or regulator asks for proof of current compliance, and the honest answer is a scramble through spreadsheets, inboxes, and an HRIS that was never told the contractor existed. If compliance data for your permanent staff lives in one place and your contractor data lives in five, an audit is where you find out. Audits are the most expensive place to learn anything.
This is the case for ongoing compliance monitoring: screening as a state you maintain, rather than a gate you pass once. For permanent staff it’s good practice. For contractors, with their shorter cycles and split accountability, it’s the only model that matches how they actually work.
One decision does most of the work, which is to screen by role risk, and let the contract type follow. Write your policy around what a person can access and affect (systems, money, vulnerable people, or physical safety), and the contractor-versus-permanent question mostly answers itself, because the same role attracts the same checks regardless of who issues the payslip.
From there, four moves close the remaining gaps.
Put the standard in the agency agreement. Name the required checks and the evidence you need before day one. If the agency screens, they screen to your specification.
Verify and record, never assume. Whoever runs the checks, a copy of the outcome lands in your system, tied to the worker’s record. “The agency has it” is where audit trails go to die.
Re-screen on re-engagement. A returning contractor is a new engagement, and one whose file has been ageing unattended. Set a validity window (many organisations use twelve months) beyond which checks rerun before the person restarts.
Keep monitoring the long engagements. Any contractor whose visa, licence, or certification can expire mid-contract belongs in the same ongoing monitoring as your permanent staff, with the same alerts when something changes.
None of this needs a separate contractor process. It needs one process with fewer exemptions.
One workforce. One standard. One view. Checkmate runs the same role-based screening for everyone who works for you, on any contract. Build check bundles around role risk, send them to a permanent hire or a contractor in the same couple of clicks, and get the results back in the same dashboard, so the standard you wrote into your policy is the standard that actually runs.
Then Ongoing Compliance keeps watching after day one. Work rights, licences, and certifications are monitored continuously, with real-time alerts when something expires or changes and scheduled re-screening at the intervals you set. Because pre-employment screening and ongoing monitoring live on the same platform, the contractor who returns next year comes back to a record you already hold, and the re-screen is a click rather than a rebuild. For the person running workforce compliance, that’s the difference between proving compliance in an audit and reconstructing it.
Where the role is the same, yes. Screening requirements follow what a person can access and affect, so a contractor in a payroll system, a clinical setting, or a safety-critical site warrants the same checks as a permanent hire in that seat. Some regimes make this explicit: Australia’s aged care worker screening rules, for example, cover contractors and subcontracted workers directly. Screening by role keeps the policy simple and defensible.
In practice, both parties hold a piece. The agency usually runs the checks, and the client usually carries the consequences if something goes wrong, which is why the split has to be written down. Your agency agreement should name the required checks, the standard they’re run to, and the evidence delivered before the contractor starts. Legal obligations vary by jurisdiction, especially for work-rights checks, so confirm where the statutory duty sits in yours.
Only if you know exactly what it covers. Agency screening runs to the agency’s own standard and provider unless your contract specifies otherwise, and “screened” can mean anything from a full background check to an identity look-up. Reliance is reasonable when the standard is contractual, evidence of completion is provided, and you hold audit rights to confirm the process is followed. Without those three, you’re trusting a default you’ve never seen.
Yes. A renewal or re-engagement is the natural checkpoint, because the original checks reflect the day they were run and nothing since. Most organisations set a validity window, commonly twelve months, after which checks rerun before a contractor restarts. For credentials that can lapse mid-engagement, such as visas, licences, and certifications, ongoing monitoring with automatic alerts is more reliable than tying everything to renewal dates.
Judge them by the role, the same as anyone else. A sole trader with access to client data, funds, or vulnerable people carries the same risk as an employee in the same position, and regulated sectors are increasingly explicit about it: Australia’s aged care screening obligations, for instance, extend to workers engaged through digital platforms. The absence of an agency also means no one else has run the checks, so the responsibility defaults to you.