Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibrarySupplier and Subcontractor Management Procedure
Contents & downloads
Nomenclature
| Term | Definition |
|---|---|
| Approved Supplier List | Westlink-maintained list of suppliers and sub-contractors that have completed pre-qualification and are authorised for engagement. |
| COI | Certificate of Insurance / Currency — evidence that a supplier holds current insurance cover (workers compensation, public liability, professional indemnity and other policies as applicable). |
| Critical Supplier | A supplier or sub-contractor whose product or service materially affects Westlink’s ability to meet customer, regulatory, WHS or environmental obligations; loss of supply would cause significant disruption, safety risk or contractual default. |
| HRWL | High Risk Work Licence — a WorkSafe-issued licence required for specified high-risk work classes (e.g. rigging, dogging, scaffolding, forklift, EWP) under WHS Regulations 2022 Part 4.5. |
| Modern Slavery | As defined in the Modern Slavery Act 2018 (Cth): slavery, servitude, forced labour, human trafficking, debt bondage, deceptive recruiting for labour or services, forced marriage, and the worst forms of child labour. |
| NCR | Non-Conformance Report — a record of a product, service or process that does not meet specified requirements, raised against a supplier or arising from supplier-provided goods or services. |
| Pre-Qualification Questionnaire | Standard set of questions issued to a prospective supplier covering WHS, environmental, quality, modern slavery, anti-bribery, financial standing and information security, used to determine suitability for the Approved Supplier List. |
| Procurement | Strategic activity of identifying needs, sourcing suppliers, negotiating terms and managing supplier relationships across the engagement lifecycle. |
| Purchasing | Transactional activity of issuing purchase orders, receipting goods or services and processing supplier invoices against an existing supplier arrangement. |
| Sub-contractor | A person or entity engaged by Westlink (or by a Westlink supplier) to perform part of the work Westlink is contracted to deliver. |
| Sub-tier Supplier | A supplier one or more tiers below the direct supplier — i.e. a supplier of Westlink’s supplier. Sub-tier exposure is relevant for modern slavery, conflict minerals and critical dependency risk. |
| Supplier Code of Conduct | Westlink’s published expectations of supplier ethical, WHS, environmental, modern slavery, anti-bribery and information security behaviour, included as §6.9 of this procedure. Suppliers acknowledge the Code on engagement and annually thereafter. |
Purpose
This procedure describes how Westlink identifies, evaluates, approves, on-boards, manages and off-boards suppliers and sub-contractors. It ensures that externally provided products, services and processes meet Westlink’s quality, WHS, environmental, modern slavery, anti-bribery and information security requirements.
This procedure satisfies ISO 9001:2015 cl.8.4 (control of externally provided processes, products and services), ISO 45001:2018 cl.8.1.4 (procurement and contractors), ISO 14001:2026 cl.8.1 (operational planning and control) and Westlink’s JOSCAR-AU contractor management commitments.
Scope
This procedure applies to all suppliers, sub-contractors, consultants and labour-hire providers supplying goods or services to Westlink, including:
-
Goods suppliers (materials, consumables, equipment, plant);
-
Service providers (engineering, transport, freight forwarding, logistics);
-
Sub-contractors performing work on Westlink-contracted scopes;
-
Professional services (legal, financial, IT, audit, consultancy);
-
Labour-hire providers and individual contractors; and
-
Suppliers performing work on customer or third-party sites under Westlink’s direction.
This procedure applies across all Westlink business units, including defence-sector engagements where additional information security and personnel screening controls apply.
Routine purchases below the critical-supplier threshold (refer §6.1) may follow a simplified purchasing path; the full pre-qualification, audit and Code of Conduct flow applies to critical suppliers and any supplier engaged on defence, customer-site or high-risk work.
References
This procedure is read in conjunction with the standards, legislation, codes of practice and internal documents listed in §8 Applicable Standards and Legislation. Critical external references include ISO 9001:2015 cl.8.4, ISO 45001:2018 cl.8.1.4, ISO 14001:2026 cl.8.1, the Modern Slavery Act 2018 (Cth), the Competition and Consumer Act 2010 (Cth), the Privacy Act 1988 (Cth), the WHS Act 2020 (WA), AS ISO 37001:2016 (anti-bribery management systems) and the JOSCAR-AU accreditation contractor-management cluster.
Definitions
Defined terms used in this procedure are listed in the Nomenclature table in the front matter. Where a term has a statutory definition (e.g. Modern Slavery under the Modern Slavery Act 2018 (Cth)) the statutory definition applies.
Roles and Responsibilities
The following roles have specific responsibilities under this procedure. All other employees and contractors must comply with the procedure where it applies to their work.
| Role | Responsibility | When |
|---|---|---|
| CEO | Approve engagement of critical suppliers and sub-contractors. Approve exceptions to this procedure. Authorise removal of a supplier from the Approved Supplier List for cause. | Critical supplier engagement, exception, removal-for-cause. |
| Operations Manager | Owner of the Approved Supplier List. Approve non-critical suppliers. Maintain supplier records, performance data, audit schedule and induction records. Initiate supplier audits and reviews. | Ongoing; annual review. |
| Financial Controller | Validate Certificates of Insurance / Currency at on-boarding and on each renewal. Verify supplier financial standing as part of pre-qualification. | On-boarding, COI renewal cycles, annual review. |
| Requisitioner (any employee initiating engagement) | Identify the need for a supplier. Confirm whether the engagement requires a critical-supplier flow (refer §6.1). Issue the Pre-Qualification Questionnaire and collate responses. | At start of any new engagement. |
| Project Manager | Verify supplier currency before site mobilisation. Ensure site inductions completed. Monitor supplier performance against contract KPIs. Escalate NCRs to Operations Manager. | Pre-mobilisation; throughout the engagement. |
| QHSE Manager | Review WHS, environmental and quality content of supplier pre-qualification responses. Lead supplier audits. Investigate supplier-related incidents and NCRs. | Pre-qualification, audit cycle, post-incident. |
| Privacy Officer / CSO | Review information security content of supplier pre-qualification responses where the supplier will handle Westlink personal information or OFFICIAL/OFFICIAL:Sensitive data. | Pre-qualification (defence and personal-information scopes only). |
| Suppliers and Sub-contractors | Complete the Pre-Qualification Questionnaire truthfully. Provide current Certificates of Insurance and HRWL evidence. Sign the Supplier Code of Conduct on engagement and annually. Report changes in capability, ownership, insurance or compliance status. | On-boarding, annual, and on change. |
Procedure
Identifying the Need for a Critical Supplier
The Requisitioner must determine, at the start of any new supplier engagement, whether the supplier is critical. A supplier is critical if one or more of the following applies:
-
The goods or services are essential to delivery of a customer contract;
-
The supplier performs work on a Westlink or customer site (WHS exposure);
-
The supplier performs high-risk work as defined in WHS Regulations 2022 Part 4.5;
-
The supplier will handle Westlink personal information or OFFICIAL / OFFICIAL:Sensitive data;
-
The engagement value is material to Westlink, requiring approval at Operations Manager or CEO level;
-
Loss of supply would cause material disruption, contractual default or safety risk; or
-
The supplier sits in the defence supply chain (DISP-aligned controls apply).
If any criterion applies, the supplier is critical and the full pre-qualification, audit and Code of Conduct flow in §6.2 to §6.10 must be completed before the supplier is engaged. Non-critical suppliers may follow the simplified purchasing flow.
The Operations Manager maintains an indicative list of supplier categories that are treated as critical by default (e.g. transport sub-contractors, rigging contractors, defence-cleared service providers, IT-managed-service providers).
Pre-Qualification and Assessment
All critical suppliers must complete the Westlink Supplier Pre-Qualification Questionnaire before engagement. The Requisitioner issues the questionnaire and collates responses; the Operations Manager (with QHSE Manager and Financial Controller as required) reviews and makes the pre-qualification decision.
Supplier Pre-Qualification Questionnaire
The questionnaire collects, as a minimum:
-
Legal entity, ABN, ownership, key personnel and beneficial owner declarations;
-
Certificate of Insurance evidence (workers compensation, public liability, professional indemnity, motor where applicable);
-
ISO 9001, ISO 45001, ISO 14001 and ISO 27001 certification status (or equivalent management system evidence);
-
WHS policy, safety statistics (LTIFR, TRIFR) and current high-risk work licences held;
-
Environmental policy and history of significant environmental incidents or breaches;
-
Modern slavery statement or response (refer Modern Slavery Act 2018 (Cth) s.16 criteria);
-
Anti-bribery and conflict of interest declarations (aligned with AS ISO 37001:2016);
-
Financial standing — last two years’ financial statements or a credit reference for material engagements;
-
Information security posture where personal information or OFFICIAL/OFFICIAL:Sensitive data will be handled;
-
Sub-tier supplier disclosure for engagements where sub-tier exposure is material; and
-
Acknowledgement of the Westlink Supplier Code of Conduct (§6.9).
Evaluation Criteria
Pre-qualification responses are evaluated against the following criteria. Where a supplier does not meet a criterion, the Operations Manager records the gap and either declines the supplier, applies a corrective-action condition (timeline and evidence required), or escalates to the CEO for exception approval.
| Criterion | Acceptance Threshold | Evidence Required |
|---|---|---|
| Modern slavery | Statement consistent with Modern Slavery Act 2018 (Cth) s.16 criteria; no adverse findings against the supplier or its sub-tier suppliers. | Modern Slavery Statement (if reporting entity) or written response to Westlink modern slavery questions; supplier acknowledgement of §6.9. |
| Work Health and Safety | Current WHS management system (ISO 45001 or equivalent); LTIFR within industry norms; current HRWL where applicable; no current improvement or prohibition notices. | WHS policy, safety statistics, HRWL copies, WorkSafe notice declaration. |
| Environment | Current environmental management system (ISO 14001 or equivalent); no current EPA or DWER notices; controls for waste, emissions and spills. | Environmental policy, incident history declaration, relevant licences. |
| Quality | Current quality management system (ISO 9001 or equivalent) appropriate to the scope; documented inspection / test regime where applicable. | ISO 9001 certificate or equivalent evidence; sample quality records on request. |
| Anti-bribery and conflict of interest | Anti-bribery policy aligned with AS ISO 37001:2016; declaration of any current or prospective conflict of interest with Westlink personnel. | Policy copy or declaration; signed Code of Conduct acknowledgement (§6.9). |
| Financial standing | No material indicator of insolvency, sustained loss-making or inability to perform. | Last two years’ financial statements (material engagements only) or independent credit reference. |
| Information security | Demonstrated controls aligned with ISO 27001 or ASD Essential Eight for engagements handling Westlink personal information or OFFICIAL/OFFICIAL:Sensitive data. | ISO 27001 certificate, IRAP letter, or completed Westlink information security questionnaire. |
| Sub-tier exposure | Disclosure of sub-tier suppliers material to the engagement; flow-down of Westlink Code of Conduct to those sub-tier suppliers. | Sub-tier supplier list (engagements where material); written flow-down confirmation. |
Acceptance Criteria for Approved Suppliers
A supplier is added to the Approved Supplier List only when all of the following conditions are met:
-
Pre-Qualification Questionnaire complete and reviewed;
-
Certificates of Insurance current and validated by the Financial Controller (refer §6.3);
-
All required HRWLs sighted and recorded (refer §6.4);
-
Signed Supplier Code of Conduct on file (refer §6.9);
-
Evaluation criteria scored as acceptable or carrying a documented corrective-action condition with a closure date;
-
For critical suppliers — CEO written approval recorded;
-
Supplier record created in the Westlink Approved Supplier List and CRM; and
-
Initial review date set (no later than 12 months from approval).
Engagements with suppliers not on the Approved Supplier List are not permitted, except by documented CEO exception. Exceptions are recorded with rationale, time limit, and the date by which the supplier must complete full pre-qualification.
Insurance and Certificate of Currency Validation
The Financial Controller validates supplier Certificates of Insurance / Currency at on-boarding and on each renewal. As a minimum, suppliers must hold:
-
Workers compensation insurance, where the supplier engages workers (mandatory under state legislation);
-
Public liability insurance — minimum cover scaled to the engagement risk (typically $20M for site-based and transport work);
-
Professional indemnity insurance — for engineering, advisory, audit, IT and other professional services (typically $5M minimum);
-
Motor vehicle insurance — comprehensive cover for any vehicles used in performing the work; and
-
Marine cargo / transit insurance — where the supplier moves Westlink-controlled freight.
Certificates of Currency are stored in the supplier record. The Financial Controller maintains a renewal schedule and re-checks each certificate before its expiry. A supplier whose certificate has lapsed must not be engaged on a new scope and must be suspended from active work until evidence of renewal is received.
Insurance limits below the Westlink threshold may be accepted only with documented Operations Manager approval, taking into account the engagement risk and any customer contractual requirements. Where a customer contract specifies higher limits, the customer requirement applies.
High Risk Work Licence Verification
Where supplier personnel will perform high-risk work as defined in WHS Regulations 2022 Part 4.5, the Project Manager (or Operations Manager) must sight and record evidence of a current HRWL for each individual before that person commences work.
HRWL verification covers, as applicable:
-
Scaffolding (basic, intermediate, advanced);
-
Dogging and rigging (basic, intermediate, advanced);
-
Crane operation (slewing, non-slewing, tower);
-
Forklift operation;
-
Elevating work platform (boom-type EWP > 11m);
-
Pressure equipment operation;
-
Confined space entry (where licensed work applies); and
-
Any other high-risk class identified in WHS Regulations 2022 Schedule 3.
The Project Manager records each licence (licence number, class, holder, expiry) in the project induction record. Photocopies or photographs of the licence are retained in the supplier record. A person whose licence has expired must not perform the relevant high-risk work.
Approval and On-Boarding
Once pre-qualification is complete and acceptance criteria met, the Operations Manager approves the supplier and adds them to the Approved Supplier List. For critical suppliers the CEO’s written approval is required and is recorded against the supplier.
The on-boarding step includes:
-
Creating the supplier record in the Westlink CRM and finance system;
-
Adding the supplier to the Approved Supplier List with category, status and review date;
-
Issuing a purchase order or framework agreement covering the agreed scope and terms;
-
Recording the signed Supplier Code of Conduct (refer §6.9);
-
Scheduling the first performance review (refer §6.7); and
-
Scheduling any required audit (refer §6.8).
Outsourced processes — work performed by a supplier that would otherwise be performed by Westlink and that affects Westlink’s management system outputs — are documented in the supplier record with the controls Westlink applies (specification, inspection, audit, performance review). The Operations Manager retains accountability for the conformity of outsourced work.
Site Induction for Contractors
All contractor personnel must complete the Westlink site induction before commencing work at a Westlink workplace, a Westlink-controlled site, or a customer site where Westlink directs the work.
The induction covers, as a minimum:
-
Site hazards, controls and emergency procedures (specific to the location and scope);
-
Westlink WHS rules, drug and alcohol policy and fitness-for-work requirements;
-
Incident, hazard and near-miss reporting per QHSE-PRO-001;
-
Environmental controls (waste, spills, emissions, sensitive receptors);
-
Quality and inspection requirements specific to the scope;
-
Information security expectations where the supplier handles Westlink data;
-
Anti-bribery and Code of Conduct expectations (refer §6.9); and
-
Coordination arrangements where multiple contractors share the workplace (consultation, cooperation and coordination duty under WHS Act 2020 (WA) s.46).
Induction records (name, role, supplier, date, content delivered, evidence of competency where applicable) are maintained in the project induction record. A person who has not completed the induction must not commence work.
Ongoing Performance Management
Supplier performance is measured throughout the engagement and reviewed formally at least annually. The Operations Manager owns the performance management process; Project Managers provide engagement-level performance data.
Performance KPIs
Supplier performance is measured against the following KPI categories:
| KPI | Measure | Target / Trigger |
|---|---|---|
| On-time delivery | Percentage of deliveries on or before the agreed date. | Target ≥ 95%; below 90% triggers performance review. |
| Quality conformance | Number of NCRs raised against supplier-provided goods or services. | Trigger: any critical NCR, or 3+ NCRs in 12 months. |
| WHS performance | Recordable incidents, near misses and any notifiable incident arising from supplier work. | Trigger: any notifiable incident or fatality; any serious-injury class. |
| Environmental performance | Reportable environmental incidents (refer EP Act 1986 (WA) s.72). | Trigger: any reportable environmental incident. |
| Contract compliance | Compliance with commercial, insurance, HRWL and Code of Conduct obligations. | Trigger: lapsed insurance, expired HRWL, Code of Conduct breach. |
| Modern slavery and ethics | Modern slavery, bribery, or ethics-related allegations or findings concerning the supplier. | Trigger: any credible allegation; mandatory review on finding. |
Annual Review
Each critical supplier is reviewed at least annually. The review covers KPI performance, NCR history, incident history, audit outcomes, insurance and HRWL currency, Code of Conduct acknowledgement, and any changes in scope, ownership or sub-tier exposure. The review outcome is one of: continue, conditional continuation (with documented corrective actions), suspend, or remove from the Approved Supplier List.
Supplier performance is reported into the annual Management Review Meeting as required by ISO 9001:2015 cl.9.3, ISO 45001:2018 cl.9.3 and ISO 14001:2026 cl.9.3.
NCR Escalation
NCRs raised against a supplier are recorded against the supplier record and managed under QHSE-PRO-001 corrective action processes. Critical NCRs are escalated to the Operations Manager and (where contractual or safety-significant) to the CEO. Repeated or unresolved NCRs trigger an audit (refer §6.8) or removal from the Approved Supplier List.
Supplier Audits
The Operations Manager maintains a supplier audit schedule. Critical suppliers are audited on a risk-based cadence — typically every two years for high-risk suppliers (defence, transport sub-contractors, IT-managed-service) and on engagement plus event-driven for others.
Audit Schedule
Audit triggers include:
-
Scheduled cycle (per supplier category);
-
Critical NCR, customer complaint or recurring NCR pattern;
-
Notifiable incident involving the supplier;
-
Significant change in supplier scope, ownership, key personnel or sub-tier;
-
Code of Conduct breach or credible allegation; and
-
Customer or regulator request.
Audit Scope
Audit scope is risk-based and may cover any of the following:
-
Work Health and Safety — WHS management system, HRWL currency, recent incident handling, site safety practice;
-
Quality — process control, inspection / test, document control, NCR management;
-
Environment — environmental controls, waste, spills, regulator notices;
-
Modern slavery — labour practices, recruitment channels, sub-tier visibility;
-
Anti-bribery — controls aligned with AS ISO 37001:2016, gift and hospitality register, third-party due diligence;
-
Information security — where the supplier handles personal information or OFFICIAL/OFFICIAL:Sensitive data; and
-
Outsourced process control — where Westlink has outsourced a management-system process to the supplier.
Audit findings are recorded, communicated to the supplier and tracked to closure. Major findings may trigger immediate suspension or removal from the Approved Supplier List. Audit reports are retained for seven years.
Supplier Code of Conduct
This section is the Westlink Supplier Code of Conduct. Suppliers acknowledge the Code on engagement, on renewal of the supplier relationship and at least annually. Acknowledgement is a condition of remaining on the Approved Supplier List.
Westlink expects its suppliers, sub-contractors, consultants and labour-hire providers to operate to standards consistent with Westlink’s own policies and obligations. Where a Westlink expectation is higher than the legal minimum in a supplier’s jurisdiction, Westlink’s expectation applies for work performed for Westlink.
Ethical Conduct
Suppliers must act with integrity, honesty and fairness. Suppliers must comply with all applicable laws and regulations in the jurisdictions in which they operate. Suppliers must not engage in or facilitate fraud, deception or misrepresentation in dealings with Westlink, Westlink customers, or any regulator.
Modern Slavery and Human Rights
Suppliers must not engage in, or knowingly tolerate within their operations or supply chain, any form of modern slavery as defined in the Modern Slavery Act 2018 (Cth) — slavery, servitude, forced labour, human trafficking, debt bondage, deceptive recruiting for labour or services, forced marriage, or the worst forms of child labour.
Suppliers must:
-
Verify the right-to-work status of all personnel performing Westlink-related work;
-
Pay at or above legal minimum wages and provide lawful working conditions;
-
Not charge workers recruitment fees or retain identity documents;
-
Apply the same modern slavery expectations to their own sub-tier suppliers (flow-down);
-
Cooperate with Westlink modern slavery due diligence requests and (where applicable) provide a copy of their Modern Slavery Statement; and
-
Respect human rights consistent with the UN Guiding Principles on Business and Human Rights.
Anti-Bribery and Conflict of Interest
Suppliers must not offer, give, solicit or accept any bribe, secret commission, kickback or improper benefit in connection with Westlink business. This applies to dealings with Westlink personnel, Westlink customers, public officials and any other party.
Suppliers must operate controls consistent with AS ISO 37001:2016 (anti-bribery management systems) proportionate to the bribery risk they face. Suppliers must declare any current or prospective conflict of interest involving Westlink personnel (e.g. a Westlink employee with a material interest in the supplier) and must apply that flow-down expectation to their own sub-tier suppliers and agents.
The Westlink anti-bribery policy (GOV-POL-012) governs Westlink personnel; this section applies the equivalent expectations to suppliers.
Work Health and Safety
Suppliers must provide and maintain a safe workplace for their workers and for any person affected by their work. As a minimum, suppliers must:
-
Comply with the WHS Act 2020 (WA) and WHS Regulations 2022 (or equivalent in their jurisdiction);
-
Operate a WHS management system appropriate to their scale and risk (ISO 45001 or equivalent);
-
Hold current HRWLs for all licensed work classes;
-
Report incidents, hazards and near misses arising from Westlink-related work in accordance with QHSE-PRO-001;
-
Cooperate with Westlink on consultation, cooperation and coordination where workplaces overlap (WHS Act 2020 s.46);
-
Cooperate with Westlink and regulator investigations following any notifiable incident; and
-
Apply the same WHS expectations to their own sub-tier suppliers and labour providers.
Environment
Suppliers must comply with environmental laws and operate to standards consistent with ISO 14001 or equivalent. Suppliers must:
-
Identify and control the significant environmental aspects of their work for Westlink;
-
Manage waste, emissions, spills and chemicals lawfully and in accordance with site rules;
-
Report any reportable environmental incident under the Environmental Protection Act 1986 (WA) s.72 or equivalent; and
-
Apply environmental flow-down expectations to their own sub-tier suppliers.
Information Security and Privacy
Suppliers that handle Westlink personal information, customer information, or OFFICIAL / OFFICIAL:Sensitive data must:
-
Operate information security controls aligned with ISO 27001 and ASD Essential Eight (at the level appropriate to the data sensitivity);
-
Comply with the Privacy Act 1988 (Cth) Australian Privacy Principles in relation to personal information handled for Westlink;
-
Apply Westlink-provided handling requirements for defence-classified information;
-
Report suspected or actual information security incidents to Westlink within 24 hours, including any data breach that may be notifiable under the Privacy Act 1988 Part IIIC; and
-
Not subcontract handling of Westlink data without Westlink written approval.
Acknowledgement
Suppliers acknowledge this Code on engagement, on each renewal of the supplier relationship and at least annually. Acknowledgement is recorded against the supplier record. A supplier that refuses to acknowledge the Code, or that materially breaches it, will be removed from the Approved Supplier List.
Reporting Non-Compliance
Suppliers, their workers, and any third party may report a suspected breach of this Code (or of any law or Westlink policy) through the Westlink whistleblower channel established under the Whistleblower Policy (GOV-POL-018). Reports may be made confidentially and may be made anonymously.
Westlink does not tolerate detrimental conduct against any person who makes a report in good faith. Suppliers must not retaliate against their workers for making such a report. The Whistleblower Policy (GOV-POL-018) is the controlling Westlink document for the channel and associated protections; this section refers suppliers to that channel rather than establishing a parallel process.
Critical Supplier and Sub-Tier Dependency Tracking
Westlink maintains visibility of critical-supplier and sub-tier dependencies to manage business continuity, modern slavery and supply-chain security risk.
For each critical supplier, the Operations Manager records:
-
The Westlink scopes and customer contracts that depend on the supplier;
-
Identified sub-tier suppliers that are material to the engagement;
-
Single-point-of-failure exposures (no alternative supplier, no immediate substitute);
-
Geographic and concentration risk (where dependency is concentrated in a single region or jurisdiction);
-
Modern slavery and labour-rights risk indicators for the supplier and disclosed sub-tier; and
-
Information security and defence supply-chain risk (where applicable).
Critical-supplier and sub-tier risk is reviewed annually as an input to the Management Review Meeting and on any material event (e.g. supplier insolvency, regulator action, geopolitical event, customer or contractual change). Mitigations may include identifying alternative suppliers, increasing inventory, contractual change, or de-scoping the dependency.
Supplier Off-Boarding and Termination
A supplier is off-boarded when the engagement ends, the supplier is removed from the Approved Supplier List, or the supplier is terminated for cause.
The off-boarding step covers:
-
Closing out any open purchase orders, contracts and invoices;
-
Recovering any Westlink-owned assets, equipment, materials or documentation;
-
Confirming return or destruction of Westlink data held by the supplier (including any OFFICIAL or OFFICIAL:Sensitive data);
-
Closing site access, security passes and system access rights;
-
Capturing lessons learned and updating the supplier record with the off-boarding outcome; and
-
Updating the Approved Supplier List status and the CRM.
Termination for cause (e.g. material Code of Conduct breach, repeated unresolved NCRs, insolvency, fraud) requires Operations Manager decision and, for critical suppliers, CEO approval. The rationale and supporting evidence are recorded in the supplier record. Where the termination involves a notifiable matter (e.g. modern slavery, bribery), the CEO determines whether external reporting is required.
Applicable Standards and Legislation
-
ISO 9001:2015 Quality Management Systems — Requirements — cl. 5.2 (policy), cl. 7.5 (documented information), cl. 10.2 (nonconformity and corrective action)
-
ISO 45001:2018 Occupational Health and Safety Management Systems — Requirements — cl. 5.2 (policy), cl. 6.1 (hazard identification), cl. 8.2 (emergency preparedness), cl. 10.2 (incident investigation)
-
ISO 14001:2026 Environmental Management Systems — Requirements — cl. 5.2 (policy), cl. 6.1.2 (environmental aspects), cl. 8.1 (operational controls and life cycle perspective), cl. 9.1.1 (monitoring, measurement and calibrated equipment), cl. 10.1 (continual improvement)
-
ISO 31000:2018 Risk Management — Guidelines — Risk assessment methodology, risk treatment, monitoring and review
-
ISO/IEC 27001:2022 Information Security Management Systems — Requirements — cl. 6.1 (risk assessment), cl. 8.2 (risk treatment), A.5.26 (incident response)
-
ISO 37001:2016 Anti-Bribery Management Systems (informative reference)
-
Work Health and Safety Act 2020 (WA) — s.19–27 (duties), Part 3 ss.35–39 (incident notification)
-
Work Health and Safety (General) Regulations 2022 (WA) — Reg. 35–38 (risk management), Reg. 54–64 (falls), Reg. 66–93 (confined spaces), Reg. 337–419 (hazardous chemicals), Reg. 699–704 (incident notification)
-
Environmental Protection Act 1986 (WA) — s.72 (reporting environmental incidents), s.73 (authorised officer powers)
-
Privacy Act 1988 (Cth) — APPs 1–13, Part IIIC (NDB scheme), s.26WK–WR
-
Modern Slavery Act 2018 (Cth) — s.13–16 (reporting entity obligations), s.3 (modern slavery definition)
-
UN Guiding Principles on Business and Human Rights (2011)
-
JOSCAR — Joint Supply Chain Accreditation Register — Supply chain assurance requirements across security, governance, privacy, ethics
-
Defence Industry Security Program (DISP) — Security Governance Framework — Membership obligations, security incident reporting
-
AS 4811-2022 Workforce Screening — Identity verification, integrity screening, credentials screening, spent convictions, screening tiers, records management
-
Code of Practice: How to Manage Work Health and Safety Risks (WA, 2022)
-
Code of Practice: Work Health and Safety Consultation, Cooperation and Coordination (WA, 2022)
Compliance coverage — cited by 33 requirements across 5 frameworks
Financial Crime — Proceeds of Crime, Terrorism Financing, Foreign Bribery, Modern Slavery(2)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| FC-MS-01 | Modern Slavery Act 2018 (Cth) s.5 (reporting threshold) | Partial | Medium | §6.2, 6.9QHSE-PRO-002 §6.2.2 modern slavery evaluation criteria and §6.9 Supplier Code of Conduct apply Modern Slavery Act 2018 (Cth) reporting-entity expectations to Westlink suppliers and sub-tier. |
| FC-MS-02 | Modern Slavery Act 2018 s.16 (mandatory reporting criteria) | Partial | Medium | §6.2, 6.9QHSE-PRO-002 §6.2.2 evaluation criteria and §6.9 Code of Conduct cover Modern Slavery Statement mandatory criteria (identity, structure, supply-chain risk, due diligence and remediation, effectiveness, consultation) at the supplier flow-down level. |
ISO 14001:2026(5)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO14001-2026-8.1-01 | 8.1 | Full | §6QHSE-PRO-002 establishes operating criteria and controls for supplier engagement processes that affect environmental outcomes. | |
| ISO14001-2026-8.1-03 | 8.1 | Full | §6.2QHSE-PRO-002 §6.2.2 environmental evaluation criteria ensure externally provided processes, products and services relevant to environmental outcomes are controlled or influenced. | |
| ISO14001-2026-8.1-04 | 8.1 | Full | §6.5QHSE-PRO-002 §6.5 defines the type and extent of environmental control / influence applied within the environmental management system. | |
| ISO14001-2026-8.1-05 | 8.1 | Full | §6.7, 6.9QHSE-PRO-002 §6.7 monitors environmental performance and §6.9 flows environmental expectations to suppliers and sub-tier consistent with a life-cycle perspective. | |
| ISO14001-2026-8.1-06 | 8.1 | Full | §6.8QHSE-PRO-002 §6.8 audit programme retains documented information on supplier environmental controls; §6.7 records performance reviews. |
ISO 45001:2018(7)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO45001-2018-8.1.4.1-01 | 8.1.4.1 | Full | §6.2QHSE-PRO-002 §6.2 establishes the procurement process to ensure conformity of products and services to the OH&S management system. | |
| ISO45001-2018-8.1.4.2-01 | 8.1.4.2 | Full | §6.6QHSE-PRO-002 §6.6 coordinates procurement with contractors, identifies hazards and controls OH&S risks across contractor / Westlink / interested-party activities. | |
| ISO45001-2018-8.1.4.2-02 | 8.1.4.2 | Full | §6.6, 6.9QHSE-PRO-002 §6.6 induction and §6.9 Code of Conduct ensure contractor workers meet the OH&S management system requirements. | |
| ISO45001-2018-8.1.4.2-03 | 8.1.4.2 | Full | §6.2.2QHSE-PRO-002 §6.2.2 evaluation criteria include OH&S criteria for selection of contractors. | |
| ISO45001-2018-8.1.4.3-01 | 8.1.4.3 | Full | §6.5QHSE-PRO-002 §6.5 ensures outsourced functions and processes are controlled (Operations Manager accountable for outsourced work conformity). | |
| ISO45001-2018-8.1.4.3-02 | 8.1.4.3 | Partial | §6.5, 6.6QHSE-PRO-002 §6.5 and §6.6 align outsourcing arrangements with WHS legal requirements and OH&S management system outcomes. | |
| ISO45001-2018-8.1.4.3-03 | 8.1.4.3 | Full | §6.5QHSE-PRO-002 §6.5 defines the type and degree of control applied to outsourced functions within the OH&S management system. |
ISO 9001:2015(8)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-8.4.1-01 | 8.4.1 | Full | §6QHSE-PRO-002 establishes the controls applied to externally provided processes, products and services across the supplier engagement lifecycle. | |
| ISO9001-2015-8.4.1-02 | 8.4.1 | Partial | Medium | §6.1QHSE-PRO-002 §6.1 critical-supplier criteria determine the level of control applied to each engagement. |
| ISO9001-2015-8.4.1-03 | 8.4.1 | Full | §6.2QHSE-PRO-002 §6.2 defines evaluation, selection and re-evaluation criteria for external providers; §6.7 documents ongoing monitoring. | |
| ISO9001-2015-8.4.1-04 | 8.4.1 | Full | §6.5, 6.7QHSE-PRO-002 §6.5 records the supplier and on-boarding decision; §6.7 retains performance review records. | |
| ISO9001-2015-8.4.2-01 | 8.4.2 | Full | §6.2, 6.5QHSE-PRO-002 §6.2.3 acceptance criteria and §6.5 on-boarding controls ensure externally provided processes do not adversely affect Westlink delivery. | |
| ISO9001-2015-8.4.2-02 | 8.4.2 | Partial | Medium | §6.5QHSE-PRO-002 §6.5 documents the type and extent of control applied to outsourced processes and the controls applied to external providers. |
| ISO9001-2015-8.4.3-01 | 8.4.3 | Partial | High | §6.5, 6.7QHSE-PRO-002 §6.5 (purchase orders and framework agreements) and §6.7 ensure requirements are adequate before communication to external providers. |
| ISO9001-2015-8.4.3-02 | 8.4.3 | Partial | High | §6.7, 6.9QHSE-PRO-002 §6.7 communicates performance requirements to external providers; §6.9 communicates Code of Conduct expectations. |
JOSCAR-AU 2026(11)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q1.4.8 | Q1.4.8 | Full | Supplier and Subcontractor Management Procedure §6.10 records critical-supplier dependencies and sub-tier visibility for critical engagements. | |
| JOSCAR-Q1.8.5 | Q1.8.5 | Full | Supplier and Subcontractor Management Procedure §6.3 requires workers compensation Certificate of Currency validation at on-boarding and renewal. | |
| JOSCAR-Q2.6.15 | Q2.6.15 | Full | Supplier and Subcontractor Management Procedure §6.4 requires HRWL verification for subcontractors performing high-risk work. | |
| JOSCAR-Q2.10.1 | Q2.10.1 | Full | Supplier and Subcontractor Management Procedure documents the full pre-qualification and assessment workflow. | |
| JOSCAR-Q2.10.2.4 | Q2.10.2.4 | Full | Supplier and Subcontractor Management Procedure §6.3 requires collection and validation of Certificates of Currency. | |
| JOSCAR-Q2.10.2.5 | Q2.10.2.5 | Full | Supplier and Subcontractor Management Procedure §6.8 establishes the audit programme for critical suppliers. | |
| JOSCAR-Q2.10.2.6 | Q2.10.2.6 | Full | Supplier and Subcontractor Management Procedure §6.2.2 financial standing evaluation (last two years of financial statements or independent credit reference for material engagements) and §6.7 ongoing monitoring (material events including insolvency). | |
| JOSCAR-Q2.10.2.7 | Q2.10.2.7 | Full | Supplier and Subcontractor Management Procedure §6.6 documents the contractor site-induction process. | |
| JOSCAR-Q2.10.4 | Q2.10.4 | Full | Supplier and Subcontractor Management Procedure §6.9 is the Supplier Code of Conduct. | |
| JOSCAR-Q2.10.6 | Q2.10.6 | Full | Supplier and Subcontractor Management Procedure §6.7 documents KPI-based supplier performance measurement and re-evaluation. | |
| JOSCAR-Q2.10.8 | Q2.10.8 | Full | Supplier and Subcontractor Management Procedure §6.2.3 defines acceptance criteria for approved suppliers. |
Declared compliance references (33)
FC-MS-01FC-MS-02ISO14001-2026-8.1-01ISO14001-2026-8.1-03ISO14001-2026-8.1-04ISO14001-2026-8.1-05ISO14001-2026-8.1-06ISO45001-2018-8.1.4.1-01ISO45001-2018-8.1.4.2-01ISO45001-2018-8.1.4.2-02ISO45001-2018-8.1.4.2-03ISO45001-2018-8.1.4.3-01ISO45001-2018-8.1.4.3-02ISO45001-2018-8.1.4.3-03ISO9001-2015-8.4.1-01ISO9001-2015-8.4.1-02ISO9001-2015-8.4.1-03ISO9001-2015-8.4.1-04ISO9001-2015-8.4.2-01ISO9001-2015-8.4.2-02ISO9001-2015-8.4.3-01ISO9001-2015-8.4.3-02JOSCAR-Q1.4.8JOSCAR-Q1.8.5JOSCAR-Q2.10.1JOSCAR-Q2.10.2.4JOSCAR-Q2.10.2.5JOSCAR-Q2.10.2.6JOSCAR-Q2.10.2.7JOSCAR-Q2.10.4JOSCAR-Q2.10.6JOSCAR-Q2.10.8JOSCAR-Q2.6.15
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 26/05/2026 | WLK-GBL-SCM-PRO-001 | Supplier and Subcontractor Management Procedure | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | Initial issue in new WMS. Migrated from legacy WLK-GBL-SCM-PRO-001 Control of 3rd Party Providers; scope expanded to satisfy JOSCAR contractor-management evidence requirements (10 questions) and ISO 9001 §8.4 / ISO 45001 §8.1.4 / ISO 14001 §8.1 externally provided process controls. Supplier Code of Conduct incorporated as §6.9. |