Third-Party Management

A practical checklist of the essential documents to require in third-party management. Ensure labor, social security, and EHS compliance in your industry.
By:
Guilherme Herker
The mobilization of service providers in the industry demands agility, but never at the expense of safety. Rigidity in collecting and checking files is not mere bureaucracy: it is a defense for your company against labor liabilities, fines, and accidents on the factory floor.
When we understand what third-party management is, it becomes clear that the hiring company's compliance depends on the quality of this audit. To facilitate your team's routine, we have structured this article in a quick guide format, divided into the three essential categories of documents you should require.
1. Contractor Company Documents (Legal and Tax Compliance)
This layer ensures that the contracted company operates legally and is up to date with its financial obligations, mitigating the risk of lawsuits due to subsidiary liability.
Legal Identification: Updated Articles of Incorporation, Corporate Bylaws, and active CNPJ (taxpayer registry) card.
Certificates of Good Standing (CNDs): Debt-Free Certificates for Labor (CNDT), Social Security (INSS), FGTS, and Federal, State, and Municipal Taxes.
Payments and Associations: DCTFWEB, FGTS forms accompanied by the Employee List, in addition to DARF forms with the respective bank payment receipts.
Payroll Evidence: Analytical payroll detailed for the contract showing earnings and salaries, along with proof of salary payments.
2. Programs, Technical Reports, and eSocial
An effective risk management protects your company when outsourcing services because it ensures that the partner has mapped the hazards inherent to the activities, assessed occupational risks, and implemented preventive measures before entering your factory floor.
PGR (Risk Management Program): According to NR 01, it must include a risk inventory and action plan specific to the contract activities.
PCMSO (Occupational Health Medical Control Program): According to NR 07, this involves monitoring the occupational health of the contracted company's workers, which must be prepared based on the occupational risks identified in the PGR.
Technical Reports: LTCAT (Technical Report on Environmental Working Conditions) for social security purposes, as it proves worker exposure to harmful agents and guarantees the right to special retirement, and LIP (Unhealthiness and Hazard Report) for labor purposes, as it defines the allowance amount, being fixed at 30% for hazards and varying between 10%, 20%, or 40% for unhealthiness.
eSocial Transmission: Proof of sending the mandatory SST (Occupational Safety and Health) events (S-2210 for CAT, S-2220 for Health Monitoring, and S-2240 for Environmental Conditions).
3. Individual Worker Documents (Plant Access)
Each outsourced professional passing through the security gate must have an active and updated personal compliance file.
Association and Identification: ID, CPF, Driver's License (mandatory for drivers and machine operators), and eSocial Event S-2200 (Contractual Data).
Occupational Health: Valid ASO (Occupational Health Certificate) showing fitness for the specific role and activities (NR 33 and/or NR 35, if applicable). Complementary examinations must comply with the PCMSO (e.g., psychosocial evaluation, ECG, EEG, audiometry, and others).
Protection and Awareness: PPE delivery sheet with updated date and valid CA (Certificate of Approval) for each PPE, and Service Order (OS) referring to the employee's role in accordance with NR-01, both documents being properly signed.
Trainings (Regulatory Norms): Valid technical training certificates, containing the employee's name and signature, date and place of training, hourly load, program content, instructor qualifications, and technical manager signature according to item 1.7.1.1 of NR 01. Examples:
NR-10: Services with electricity;
NR-35: Work at heights;
NR-33: Confined spaces;
NR-12: Machinery and Equipment.
How to manage these documents efficiently?
Requiring and manually auditing this extensive list of documents via email or shared folders in Drive consumes valuable time and leaves room for serious errors, such as allowing a worker with an expired ASO or training onto the factory floor. In industrial routine, manual checking becomes a bottleneck for production and a danger to compliance.
To prevent the volume of paperwork from slowing business agility, transferring to smart processes is indispensable. Centralizing and organizing these records in a structured way is the main pillar when the company's focus is on third-party management, protecting the financial and legal health of the hirer against inspections and joint liability.
The most efficient way to sustain this strict control in the long term is by removing the analog operational burden from the technical team. High-performance industries use technology in HSE management to automate file reception, validate expiration dates using artificial intelligence, and integrate document clearances directly with the plant's physical access control.
In this way, the system ensures regulatory compliance in real-time, allowing the safety team to focus their efforts where they truly matter: on saving lives and mitigating risks directly in the field.










