Having a policy and being able to prove it was followed are two different things. Nobody asks what your process is meant to be. They ask you to show that it happened — on that date, for that person, at that site — and they usually ask on a Tuesday, about a job that ran fourteen months ago.
Most of the compliance management software development we are asked about in Australia starts exactly there. A business that is genuinely doing the right things and cannot evidence it quickly. The inductions happen. The permits get issued. The plant gets inspected. The record of all of it is spread across a shared drive, an inbox, a lever-arch folder in a site office and three spreadsheets, and assembling it for an audit costs a week of somebody's time.
Drawn AI came out of mining operations and retail operations, not a compliance consultancy. That cuts both ways, and we would rather be plain about it. It means we know what a prestart check, a site access requirement and a contractor pre-qualification pack look like in practice. It also means we build the system that captures and holds evidence — we do not tell you what your obligations are. Those come from your regulator, your industry body, your clients' contracts and your own advisers.
Mining and resources businesses are the clearest case, particularly in Queensland, where site access, competency and record-keeping expectations sit well above general workplace requirements and are enforced through audit and inspection. The same problem shows up in financial services as obligation registers, attestations and breach records. The artefacts differ. The failure mode does not.
Capabilities
What we build
Contractor induction and pre-qualification
A register of who is inducted for which site, on what version of the induction, and when it lapses. Pre-qualification packs — insurances, safety systems, references — held against the contractor rather than in whoever's inbox requested them, with gaps visible before they turn up at the gate.
Competency, licence and certification currency
High-risk work licences, tickets, verifications of competency, medicals and site-specific authorisations, each with an expiry date the system tracks. Certificates usually arrive as PDFs and phone photos, so document AI can read the details off them and flag anything that will not match the record.
Permits and work authorisations
Permit to work, isolation and lockout records, confined space, hot work, working at heights. Issued, approved, timestamped and closed out against the job and the people on it, so the record is a byproduct of the work rather than paperwork completed afterwards.
Plant and equipment registers
Plant certifications, inspections, service intervals and defect history held per asset. When an item comes up for inspection or a defect is raised against it, the system knows which sites and which jobs that asset is currently assigned to.
SWMS, prestarts and site records captured where the work happens
Prestart checks, take-5s, SWMS sign-ons, toolbox talks and site sign-ins completed on a phone or tablet at the point of work, including in areas with no reception. We cover the offline behaviour under field and mobile apps. A photo, timestamp and location attached at capture are worth more than a form filled in from memory that evening.
Incident capture, close-out and the audit trail underneath
Incidents, hazards and near misses logged quickly enough that people actually log them, then routed to an owner with corrective actions that are tracked to closure. Every record carries an immutable history: who entered it, who changed it, what changed, and when. That history is the difference between a record and evidence.
Signs this is worth looking at
Preparing for an audit takes a week of somebody's time and involves three spreadsheets.
A contractor arrived on site and nobody knew their induction had expired the previous month.
You know a ticket or licence is out of date because someone happened to notice, not because anything told you.
Corrective actions from an incident six months ago were assigned and nobody can confirm they were completed.
Permits are issued on paper and filed in a site office, and the office is a four-hour drive away.
A client's compliance questionnaire arrives and answering it accurately takes longer than the work it relates to.
How It Works
How we approach it
1
Discover
We walk through what you have to be able to prove, to whom, and how often. Client contracts, principal-contractor requirements, insurer conditions and internal policy usually generate more evidence obligations than the regulator does, and they are most often the unmapped ones.
2
Map
We document how each record is created today, who touches it, and where it ends up. This is normally where a business finds the same data entered three times, and the one record an auditor asks for never captured at all.
3
Design
We agree what the system must hold, what it must escalate, and to whom. Expiry rules and escalation paths get designed deliberately — 90, 60, 30 and 7 days to a named role, then upward if nothing happens — using the same workflow automation patterns we use elsewhere.
4
Build and integrate
We build the registers, capture forms and escalation logic, and connect them to the systems you already run — SharePoint, your ERP, payroll or rostering, and whatever holds your contractor list. Client data we host sits in Australian regions.
5
Optimise
After a few months we look at what is actually being captured and what people are working around. A control everyone bypasses is a design problem, and it is cheaper to fix once you can see it in the data.
Questions
Frequently asked questions
No, and we will not act like it. We build software. We do not interpret legislation, write your safety management system, tell you which obligations apply to your operation, or sign off that a system makes you compliant. That work belongs to your compliance manager, your industry advisers and your lawyers. We build what holds and produces the evidence they specify.
Off-the-shelf compliance platforms are a reasonable fit when your process resembles the process they were designed around. Custom is worth considering when it does not — site-specific inductions, contractual client reporting formats, or per-seat pricing for hundreds of contractors who log in twice a year. We will say if a product fits you better.
That is a design requirement rather than an afterthought. Forms are built to capture prestarts, sign-ons and incidents offline on a phone or tablet, hold them on the device, and sync when the device next reaches coverage. Records keep the time and location of capture, not the time of sync, so the audit trail reflects when the work actually happened.
Drawn AI works on a subscription: monthly billing, a three-month minimum term, and 30 days' notice to cancel. Not fixed-price project work and not hourly. The monthly figure depends on how many registers you need, how many people are capturing records in the field, and how many existing systems it connects to. We quote after discovery.
The heaviest demand is on your compliance and operations people during discovery and design, because they hold the knowledge of what must be proven. Rollout is usually staged — one register or one site first — so field crews learn one form at a time. Historical records can be migrated, but that is a scoped exercise and it is worth deciding early how far back you genuinely need.
No software can promise that, and be wary of any that says otherwise. What a system can do is make evidence complete, timestamped, attributable and fast to retrieve, which removes the most common reasons an audit goes badly. What is actually required, and whether you meet it, is a judgement for your auditor and your advisers.
Want to talk it through before committing to anything?
A first conversation costs nothing and usually ends with a clearer idea of what is worth building — sometimes that answer is “not yet”, and we will say so.