Service provider competency check: a guide for compliance teams
- Aug 2
- 9 min read

A service provider competency check is a structured, pre-engagement assessment of a supplier’s qualifications, regulatory standing, technical competency and contractual suitability — carried out before any agreement is formalised. Think of it as the pre-contract control that turns “we assume they can do this” into documented, verifiable evidence.
Three things to do right now if you are about to engage a new provider:
Request essential evidence immediately: certifications (verified against the issuing body), recent case history from comparable projects, and current insurance certificates.
Name a single internal owner for the check — one person who requests, chases and signs off the evidence, so nothing falls through the gaps.
Apply a provisional risk rating (low, medium or high) based on the scope and regulatory exposure of the work. That rating determines how deep the check needs to go before you can proceed.
The findings from this process should feed directly into your contract clauses — not sit in a folder and gather dust.
Table of Contents
Why do competency checks matter, and when should you run them?
How do you verify behaviour and performance, not just documents?
How often should you reassess providers after contract start?
How Bespokecompliancesolutions runs competency checks for Legionella and water-hygiene suppliers
Bespokecompliancesolutions: practical competency checks for water hygiene compliance
Why do competency checks matter, and when should you run them?
Competency checks reduce operational, regulatory and reputational risk by confirming a supplier can actually do what they say before work starts. A provider who looks credible on paper but lacks recent, relevant experience is a liability you have not yet discovered.

UK regulatory expectations make this explicit. The Health and Safety Executive requires dutyholders to appoint only competent contractors for work affecting health and safety — including water hygiene and Legionella control under the Approved Code of Practice L8. Regulated sectors carry additional supervisory expectations: financial services, healthcare and housing all face scrutiny over how they select and oversee third-party providers. A risk-based approach to initial due diligence — proportionate to the materiality of the service — is the standard supervisory bodies expect.
Trigger events that require a check:
Pre-engagement (always)
Contract renewal or material scope change
Incident or near-miss involving the provider
Supplier consolidation or change of key personnel
Evidence of declining performance against KPIs
One practical note on GDPR: when gathering evidence such as staff CVs, training records and personnel data, confirm you have a lawful basis for processing that information and handle it in line with your data protection policy.

What must an effective competency check actually cover?
The check must measure only the capabilities critical to the scope — assessing every minor task dilutes focus and wastes everyone’s time. Start by defining the critical tasks, then build your evaluation dimensions around those.
Evaluation dimensions to include:
Regulatory compliance and licensing status
Technical skills and sector-specific knowledge
Documented case history on comparable work
People competence (staff qualifications, supervision arrangements)
Quality management systems and documented procedures
Insurance and financial stability
Information security and data handling practices
Evidence to request and verify:
Verifiable certifications — confirmed with the issuing body, not just a scanned copy
Staff CVs and professional references
Recent case studies (within the last two to three years, not older)
Site visit reports or sample deliverables
Insurance certificates (employers’ liability, public liability, professional indemnity)
Audit reports or third-party assurance letters
A simple competency matrix ties these together. Score each dimension on a 1–4 band: 1 (absent), 2 (partial), 3 (meets requirement), 4 (exceeds). Weight the dimensions by criticality to the scope, and you have a defensible, auditable score.
How do you run a competency check step by step?
Follow a five-step workflow before awarding any work.
Define critical tasks and target competency levels. List the specific activities the provider must perform. For each, state the minimum acceptable standard.
Build the evidence request. Produce a structured RFI or checklist that maps each critical task to the evidence required. Be explicit — vague requests produce vague responses.
Collect and verify evidence. Receive submissions, then verify. Certification verification means confirming currency and authenticity with the issuing body, not just accepting a PDF.
Apply scoring and weighting. Use the competency matrix. A suggested starting weighting: critical task competence 40%, technical skills 30%, references and case history 20%, compliance posture 10%. Adjust for your sector and scope.
Decision and contract controls. Three outcomes are possible.
Decision | Condition | Next step |
Pass | All critical dimensions meet or exceed threshold | Proceed to contract with standard SLAs and KPIs |
Conditional pass | Minor gaps in non-critical areas | Agree a timebound remedial plan; include training obligations in contract |
Reject | Critical dimension below threshold; unverifiable evidence | Do not award work; document rationale for audit trail |
How do you verify behaviour and performance, not just documents?
Credentials and certifications are baseline indicators — they do not substitute for demonstrated, recent performance. A firm with many certified staff but no comparable recent caseload is often less qualified for a complex engagement than a smaller, highly experienced one.
Practical verification techniques:
Structured interviews: ask scenario-based questions that require the provider to describe how they handled a specific situation, not how they would handle a hypothetical one.
Observed demonstrations: request a live walkthrough of a critical task — water sampling procedure, tank inspection, or TMV servicing, for example.
Site visits: inspect the provider’s own facilities, equipment condition and record-keeping systems.
Sample deliverables: review an anonymised example of a completed risk assessment or audit report from a comparable project.
Reference checks: speak to previous clients and ask about outcomes, not just roles. “Did they identify issues others had missed?” is more useful than “Were they professional?”
Pro Tip: Frame interview questions around real past events: “Tell me about a time your team identified a compliance failure during a routine visit — what did you find, and what did you do?” Behaviour-focused questions reveal how skills are applied under actual conditions, not just what the provider knows in theory.
How do you turn assessment findings into contract controls?
Embed assessment outcomes into the contract so that capability gaps become managed obligations, not forgotten notes. A conditional pass with no contractual follow-through is worthless.
Key contract controls to include:
SLAs and KPIs: measurable, timebound outcomes with defined acceptable performance bands (e.g. water sampling results reported within five working days; TMV service records submitted within 48 hours of completion).
Remedial training obligations: where a gap was identified, specify the training required, the deadline and the evidence of completion.
Audit and evidence rights: the right to request updated certifications, conduct periodic onsite audits and require third-party assurance at defined intervals.
Data handling clauses: confirm GDPR-compliant data processing, data retention limits and breach notification obligations.
Termination triggers: define the specific performance failures or compliance breaches that entitle you to terminate without penalty.
CIS Controls guidance recommends that service provider management policies include classification, inventory, assessment, monitoring and decommissioning — with records maintained and ready for supervisor review. Build that into your contract from day one.
How often should you reassess providers after contract start?
Monitoring must be proportional to risk. A high-risk provider delivering safety-critical services needs quarterly scrutiny; a low-risk supplier providing administrative support can be reviewed annually.
Risk band | Suggested review cadence | Monitoring activities |
Low | Annual | Document refresh, KPI review, brief performance survey |
Medium | Six-monthly | KPI review, updated insurance/certification check, performance meeting |
High | Quarterly | Onsite audit, evidence re-submission, third-party assurance review |
CIS Controls advise classifying providers by risk and reassessing at least annually or when changes occur. For safety-critical services, annual is the floor, not the target.
Ad-hoc reassessment triggers:
Any incident or near-miss involving the provider
Regulatory update affecting the service scope
Change of key personnel or subcontractors
Major contract variation
What are the common pitfalls and red flags to act on?
The most common failure in provider assessments is over-reliance on certificates. A certificate confirms training was completed at a point in time; it says nothing about current practice, recent caseload or how skills are applied under real conditions.
Red flags that require immediate action:
Certifications that cannot be verified with the issuing body
Case history that is outdated, vague or cannot be substantiated with references
Inconsistent answers between the written submission and the interview
Missing or lapsed insurance
Refusal to allow a site visit or observed demonstration
When a red flag appears:
Seek written clarification within a defined deadline.
If clarification is unsatisfactory, require independent verification (e.g. a third-party audit or direct issuing-body confirmation).
Withhold contract award until the issue is resolved and documented.
If the provider cannot or will not resolve the issue, reject and record the rationale.
How Bespokecompliancesolutions runs competency checks for Legionella and water-hygiene suppliers
Bespokecompliancesolutions applies a risk-based competency check for Legionella services that balances documentation with observed competence. The process is practical and repeatable.
Scope critical tasks first: water sampling, cold water storage tank cleaning, TMV servicing and Legionella risk assessment writing are each treated as distinct competency areas with their own evidence requirements.
Evidence requested:
Recent Legionella risk assessments (within 24 months) from comparable premises
Water sampling results and laboratory chain-of-custody records
Staff CVs showing relevant qualifications (e.g. City & Guilds, BOHS P901/P902)
Current employers’ liability and public liability insurance certificates
References from facilities managers or compliance leads at previous sites
Verification step: Bespokecompliancesolutions carries out a site demonstration for critical tasks — observing sampling technique, equipment calibration and record completion in real conditions, not just on paper.
Scoring and contract conversion: findings are scored using the competency matrix, and any gap converts directly into a contractual obligation — a training deadline, a supervised first visit, or a specific KPI tied to evidence submission. For healthcare premises, the check is more intensive given the vulnerability of building occupants.
Sample checklist (adapt for your own use):
[ ] Certifications verified with issuing body
[ ] Recent case history confirmed with named references
[ ] Insurance certificates current and adequate for scope
[ ] Site demonstration completed and recorded
[ ] Competency matrix scored and signed off
[ ] Gaps converted to contract obligations with deadlines
[ ] Audit trail filed and accessible for regulatory review
A duty of care compliance record should capture the full evidence trail from initial request through to sign-off.
Key takeaways
A service provider competency check is only as useful as the contract controls and monitoring programme it feeds into — the assessment itself is the start, not the finish.
Point | Details |
Focus on critical capabilities | Assess only the tasks central to the scope; a bloated checklist produces noise, not insight. |
Verify behaviour, not just documents | Observed demonstrations and reference checks on outcomes reveal more than certificates alone. |
Convert gaps into obligations | Every identified gap should become a timebound contractual requirement with a defined evidence standard. |
Monitor proportionally | High-risk providers need quarterly review; low-risk suppliers can be assessed annually. |
Bespokecompliancesolutions | Applies a risk-based, evidence-led competency check for Legionella and water-hygiene services across UK sites. |
A practitioner’s view on getting this right
The gap between a competency check that protects you and one that merely looks like it does usually comes down to one thing: whether anyone actually verified the evidence, or just filed it.
Most organisations collect the right documents. Fewer confirm that the certification is current with the issuing body, that the case history references are real and contactable, or that the person named on the CV is the one who will actually turn up on site. That last point matters more than people admit. A provider can submit an impressive portfolio built on the work of staff who have since left.
The other underestimated step is the observed demonstration. It feels time-consuming, and providers sometimes push back. Do it anyway. Watching a technician carry out a water sampling procedure, or reviewing how a risk assessment is structured in real time, tells you more in 30 minutes than a folder of certificates tells you in an afternoon.
For teams with limited capacity, prioritise by risk. Start with your highest-risk providers — those delivering safety-critical services, those with access to vulnerable populations, those where a failure would trigger a regulatory notification. Get those checks done properly before extending the process to lower-risk suppliers.
The role of the compliance manager in owning this process is clear: one person requests, chases, scores and signs off. Shared ownership means no ownership.
Bespokecompliancesolutions: practical competency checks for water hygiene compliance
Compliance teams managing Legionella and water hygiene risk need providers they can verify, not just trust. Bespokecompliancesolutions offers the full range of services that sit at the heart of a competency check: Legionella risk assessments, water sampling and analysis, TMV servicing, tank cleaning and disinfection, and Legionella awareness training for your own staff and contractors.

Every engagement starts with a scoped assessment of your site’s specific requirements — no generic templates, no off-the-shelf reports. If you need to verify a supplier’s competence before awarding water hygiene work, or if you want an independent check of your current provider’s performance, the team at Bespokecompliancesolutions can carry out an on-site competency assessment and convert the findings into a clear, contractually usable report. Get in touch to request a site assessment or to discuss your supplier verification requirements.
Authoritative UK sources and further reading
A short reference list for compliance professionals who need to go deeper on standards, regulatory expectations and procurement practice.
HSE Approved Code of Practice L8 — the primary UK regulatory reference for Legionella control and competent contractor requirements. Use for legal and regulatory checks.
HSE Technical Guidance HSG274 — detailed technical guidance on water systems. Use for technical validation of provider competence in water hygiene.
CIS Controls: Service Provider Management — practical framework for classifying, assessing and monitoring service providers. Use for procurement policy and monitoring cadence.
World Bank Digital Finance: Assessment of Service Providers — supervisory guidance on proportionate, risk-based due diligence and ongoing monitoring. Useful for regulated-sector compliance teams.
ATD: What Is a Competency Assessment? — clear explanation of behaviour-focused competency assessment methodology. Use when designing your competency matrix and scoring criteria.
ICO: UK GDPR Guidance — authoritative reference for data protection obligations when collecting and processing provider personnel data during assessments.
This article provides general information for compliance professionals and does not constitute legal or regulatory advice. Confirm current requirements with the HSE, your sector regulator, or a qualified compliance professional for your specific situation.
Recommended

Comments