Risk & Compliance
Contingent Workforce Compliance Services
Written policy behind classification, co-employment posture, screening, training, access, and retention, with the evidence ready when someone asks for it.
Contingent workforce compliance covers the obligations you carry for people who work for you but are not your employees. In life sciences that surface is unusually wide. Employment and tax authorities care how workers are classified. Your quality system cares whether they were trained before touching regulated work. Your privacy obligations follow them into clinical and safety data, and your security team wants to know their access ended the day the assignment did. Viltis builds and runs the controls that keep those answers consistent, whoever the worker is and whichever site they are on.
Overview
Worker classification and co-employment posture
Classification errors get expensive because they accumulate quietly. Take an independent contractor hired directly by a manager, working full-time on site under daily direction for two years. On paper the arrangement is defensible. In an audit it is hard to explain.
We work with your legal and HR teams to write the decision rules, then build them into intake so the call gets made before onboarding, not during a dispute. Co-employment posture is handled the same way: which management activities sit with the supplier, what performance feedback looks like, and who governs tenure and conversion.
Classification criteria applied at requisition intake, with an escalation path for edge cases
Independent contractor engagement rules, including where payrolling is the safer route
Assignment tenure limits and the review that happens as a worker approaches them
Conversion policy that gives the business a legitimate route to hire good people
Guidance for managers on performance and direction that respects the supplier relationship
Overview
Screening standards that match the work
One screening package for everyone is usually too much for low-risk roles and too little for high-risk ones. We tier screening against what the assignment involves: site access, controlled substances, patient data, financial authority, federal contract obligations. That keeps the standard defensible in both directions.
The program also handles the operational questions that trip up most organizations: who pays for screening, how adverse findings get adjudicated consistently, how long a result stays valid if the worker comes back, and how records are retained under the privacy law that applies.
Overview
Qualification, training, and system access
In regulated environments, compliance failure usually looks mundane. A contractor gets quality system access on their first morning because the assignment is urgent. The required training follows two weeks later. In between, they sign records they were not yet qualified to sign.
So the program fixes the order and holds it: role-based training assigned at onboarding, completion verified before provisioning, access scoped to the assignment, deprovisioning fired by the end date held in the vendor management system. An exception needs documented approval, not an email.
Overview
Supplier flow-down and contractual obligations
Your obligations do not stop at your supplier's signature page. Confidentiality, data integrity, screening standards, record retention, insurance, subcontracting limits, breach notification: all of it has to flow down to the agencies placing workers with you, and you need to be able to check that it did.
We read incumbent supplier agreements against the standard and work the gaps into supplier onboarding and renewal cycles.
Overview
Evidence and audit readiness
A control you cannot evidence is a control you do not have. The program is built so the non-employee population, their qualification status, their access, and the documents behind all of it can be produced on request, including for assignments that closed years ago.
It saves the scramble that follows an inspection notice, or an internal audit whose scope quietly grows to include contract personnel.
Benefits
What the compliance layer prevents
Classification decided once, correctly
Rules applied at intake stop the pattern where a hard classification call gets made under deadline pressure by whoever happens to be closest to the hire.
No access without qualification
Gating provisioning on training completion removes the most common finding in regulated environments: a contractor working in systems before the record says they are ready.
Access that actually ends
Deprovisioning tied to assignment end dates, with exception reporting on accounts still open, closes a gap most unmanaged programs never notice.
Screening that stands up either way
Risk-tiered standards mean high-exposure roles are screened properly and low-risk roles are not delayed by checks the work does not warrant.
Obligations that reach your suppliers
Flow-down terms get checked at onboarding and renewal, so your data and retention requirements sit in the contract instead of in an assumption.
Evidence available on demand
Worker population, qualification status, and supporting records can be produced for auditors and inspectors without reconstructing history from email.
FAQ
Contingent workforce compliance FAQs
What is co-employment risk and how serious is it?
Co-employment is where your organization exercises enough control over a supplier's worker that you may end up sharing employer obligations. You manage it; you do not avoid it. The risk grows when tenure runs unlimited, when managers handle discipline and benefits themselves, and when nothing is written down. Clear rules, applied consistently, cover most of the exposure.
Should we apply tenure limits to contractors?
Many organizations do, but a hard limit that pushes a qualified validation engineer off a project halfway through creates its own problems. We usually suggest a tenure review trigger instead of an automatic end date. At a set point, someone looks at the assignment and decides: convert, extend with a justification, or close it.
Who is responsible for background screening - us or the supplier?
Usually the supplier screens to a standard you define in the contract, and the program checks it is done before onboarding goes ahead. The important part is that the standard is written down, the same for every supplier, and evidenced, instead of left to whatever package each agency runs by default.
Do contract workers need the same GxP training as employees?
If they do equivalent regulated work, yes. Training requirements follow the activity, not the employment relationship, so the program assigns training by role and confirms completion before the access that work needs is granted.
How long do we need to keep contractor records after an assignment ends?
That depends on the regulatory, employment, tax, and privacy requirements in each jurisdiction you operate in, plus your own retention policy. We map all of it during design, so the program keeps what it has to keep and disposes of what should not sit in a file forever.
Can you assess our current program without a full engagement?
Yes. A compliance assessment across classification, screening, qualification, access, and retention is a common standalone starting point. It gives you a prioritized gap list you can work through with or without us.
Continue
Related capabilities
Ready to talk through your program?
Bring us your current spend, supplier list, and compliance obligations. We will show you what a technology-enabled contingent workforce program would look like for your organization.