Outsourcing drug and alcohol testing to a third-party provider is a sensible decision for many Australian organisations. It provides access to trained collectors, established procedures, and laboratory relationships without the overhead of building an in-house capability. However, outsourcing the work does not outsource the risk. If your provider conducts a test improperly, uses expired equipment, or fails to maintain chain of custody, it is your organisation that bears the consequences — in Fair Work Commission proceedings, in court, and in the eyes of your workforce.
Effective provider oversight is not about micromanagement. It is about establishing clear expectations, verifying compliance, and maintaining the level of control necessary to protect your organisation’s legal position.
Due Diligence Before Engagement
Provider oversight begins before the contract is signed. A thorough due diligence process should examine:
Certifications and Accreditations
- Collector qualifications — Are all collectors trained and assessed as competent in accordance with AS/NZS 4308 and AS 4760? How frequently are they re-assessed?
- Laboratory accreditation — Does the provider’s laboratory partner hold NATA accreditation for the relevant test methods? NATA accreditation is the gold standard for laboratory reliability in Australia.
- Quality management — Does the provider operate under a certified quality management system (for example, ISO 9001)?
- Insurance — Does the provider carry adequate professional indemnity and public liability insurance?
Operational Capability
- Geographic coverage — Can the provider service all your locations, including remote sites?
- Response times — What are their standard and emergency response times?
- Capacity — Can they handle your testing volume, including peak periods and large-scale events?
- Technology — What collection and reporting systems do they use? Are records digital or paper-based?
References and Track Record
Request references from current clients in your industry. Ask specifically about:
- Documentation quality and completeness
- Response times and reliability
- How the provider handled any issues or disputes
- The provider’s willingness to participate in audits
Service Level Agreement Requirements
Your contract with the provider should include a detailed service level agreement (SLA) that specifies measurable performance standards:
- Response times — Maximum time from request to collector arrival on site, for both scheduled and urgent collections.
- Reporting turnaround — Maximum time from collection to result delivery for both screening and confirmation testing.
- Documentation standards — Chain of custody documentation must be complete, legible, and compliant with AS 4760 / AS/NZS 4308 requirements.
- Result accuracy — Laboratory result reporting must include confirmation testing methodology and reference ranges.
- Incident reporting — The provider must report any collection incidents, equipment failures, or procedural deviations within a specified timeframe.
- Audit rights — Your organisation retains the right to audit the provider’s records, procedures, and facilities at reasonable intervals.
Ongoing Monitoring
Record Audits
Conduct regular audits of the records your provider produces. Review a sample of chain of custody forms, result reports, and any incident documentation. Look for:
- Completeness — Are all mandatory fields completed?
- Consistency — Do specimen IDs, donor details, and dates match across related documents?
- Timeliness — Were results reported within SLA timeframes?
- Procedure compliance — Do observation period times, collection methods, and result interpretations comply with the relevant standards?
Quarterly audits of 10-15% of records are a reasonable starting point. Increase the frequency if issues are identified.
Collector Competency
Request evidence that all collectors assigned to your work are currently qualified and have completed refresher training within the required period. Consider requesting:
- A list of all collectors who may be assigned to your work
- Training certificates and refresher dates for each collector
- Notification when new collectors are assigned or existing collectors’ qualifications expire
Equipment Verification
Verify that the provider’s equipment meets required standards:
- Breathalyser calibration certificates current
- Collection devices within expiry dates and stored appropriately
- Point-of-care testing devices validated and maintained per manufacturer specifications
Incident Handling
How your provider handles incidents — a broken chain of custody, a challenged result, a donor complaint — reveals the quality of their operation. Your SLA should require:
- Immediate verbal notification of any incident that may affect a result’s integrity
- Written incident report within 24 hours, including root cause analysis and corrective actions
- Participation in any subsequent investigation, hearing, or legal proceeding
- Evidence that corrective actions have been implemented
Data Security
Drug test records are sensitive health information. Your provider must handle this data in accordance with the Privacy Act 1988 and applicable state legislation. Key requirements include:
- Data storage — Where is data stored? Is it hosted in Australia? What encryption is used?
- Access controls — Who within the provider’s organisation can access your data? Are access controls role-based?
- Data sharing — Under what circumstances can the provider share your data with third parties?
- Data retention and destruction — What is the provider’s retention policy? How is data destroyed when no longer needed?
- Breach notification — The provider must notify you immediately of any data breach affecting your records, in addition to their obligations under the Notifiable Data Breaches scheme.
Regular Review Process
Establish a formal, scheduled review process with your provider:
- Quarterly operational reviews — SLA performance, record quality, any issues or incidents.
- Annual strategic review — Overall provider performance, contract terms, pricing, emerging needs, and any changes to your testing requirements.
- Annual audit — Formal audit of the provider’s procedures, records, equipment, and certifications.
Document every review meeting and retain the records. This documentation demonstrates that your organisation is actively managing its testing program, not simply delegating it and hoping for the best.
When to Change Providers
Red flags that indicate it may be time to consider an alternative provider include:
- Repeated SLA breaches without satisfactory corrective action
- Persistent documentation quality issues
- Collectors arriving on site with expired equipment
- Results that are challenged due to procedural failures by the provider
- Reluctance to participate in audits or provide requested documentation
- Data security concerns or breaches
Changing providers is disruptive, so it should not be undertaken lightly. However, the cost of continuing with a non-compliant provider is always greater than the cost of transition.
Looking for a platform that gives you full visibility into your testing program, whether managed in-house or through a provider? Visit fairtest.com.au to start your free trial and take control of your testing data.