← All resources

RTO Subcontractor Compliance: A COO's Accountability Guide

7 October 2026 · 8 min read

Subcontracting moves the delivery, not the accountability. Under the Standards for RTOs 2025, your CEO signs an annual declaration that covers third-party services, and ASQA expects it to rest on verified evidence. The COO's real exposure isn't the contract. It's whether anyone can show, from one place and on demand, what your partners are doing this week.

Why this lands on your desk

Your CEO signs the Annual Declaration on Compliance. You build the machinery that makes that signature defensible.

ASQA's Accountability Practice Guide says preparation for the declaration must cover the whole scope of registration, including all services delivered by third parties. It also says the CEO completes the declaration having verified the compliance of those third parties' systems, practices and processes. The Standards for RTOs 2025 came into full regulatory effect on 1 July 2025, so this is current expectation, not a transition-period courtesy.

"Verified" is the operative word. A signed partner agreement is not verification. Verification is a routine that produces evidence, and routines are operations.

What the Standards leave with the RTO

ASQA's 2025 Standards FAQs are blunt: RTOs are responsible for managing their third-party arrangements. Three other threads in ASQA's material matter to operations.

  • Complaints and feedback. The 2025 Standards require you to capture feedback and complaints about the organisation, any third parties, and anyone employed or contracted by the organisation. That process has to work across partner boundaries, not only inside your own student services team.
  • Marketing and recruitment. ASQA's Information Practice Guide lists a known risk: inadequate oversight of, and formal arrangements with, third parties that market to or recruit students, including where those arrangements aren't made clear to students.
  • Outsourced delivery. ASQA's 2025-26 environmental scan reported providers outsourcing elements of onshore training and assessment to offshore third parties. It flagged risks to quality, currency and consistency, and noted that oversight becomes harder. It also noted ESOS providers being bought or operating in informal groups, which can in some cases conceal ownership or control.

There is a governance angle too. As The Sector reported on ASQA's 7 May 2026 statement, failing to meet Fit and Proper Person Requirements or material change notification requirements means non-compliance with the 2025 Standards. Significant events arising through a third-party arrangement can be relevant if they affect your capacity to meet your obligations. Someone has to be watching for those events, and it won't be the partner's marketing team.

Where oversight actually breaks

It rarely breaks at the contract. It breaks in the operating rhythm. Most of what we see described across the sector falls into three patterns.

  1. Partner data arrives late or in different formats. Someone rekeys it, reconciles it and chases it. The RTO's picture of partner activity is always a few weeks old.
  2. Partner practice sits outside your quality loop. Your validation, moderation and continuous improvement cycles cover your own trainers and assessors. The partner's work gets a lighter touch, or none.
  3. Oversight lives in a few heads. One compliance lead knows which partner is slow on assessment records. One operations manager knows who to ring. When either leaves, the oversight leaves with them.

These are your standing pain points, scaled across organisational boundaries: disconnected systems, duplicate entry, knowledge trapped in individuals. A partner just makes each one harder to see.

ASQA's enforcement staff have reportedly described "third-party arrangements with no monitoring" in critically non-compliant RTOs. Notes from ASQA's March 2026 update, which are secondary and worth checking against ASQA directly, say third-party arrangements carry more risk when the third party isn't monitored. They also say regular monitoring, data and feedback review and early intervention are expected.

Quarterly reporting will make the gaps show sooner

The VET Information Standard replaces AVETMISS under the VET Data Streamlining Program. NCVER describes a shift from minimum annual, point-in-time reporting to minimum quarterly, status-based reporting, with new validation and data quality rules. The amendment instrument takes effect 1 October 2026. RTOs transition by 1 January 2029, though some sources say 31 December 2028. STA-arrangement RTOs follow their STA's date, and intent to transition must be notified to NCVER at least three months ahead.

The operational consequence is simple. An annual scramble can hide a messy partner data flow. A quarterly cycle can't.

One honest caveat. I couldn't find authoritative guidance on how subcontracted activity is split between the RTO and the third party under the new model. Confirm that with NCVER, and with your STA if one applies, before you design your partner data flows around an assumption.

What defensible oversight looks like

You don't need a heroic effort. You need a small set of routines that run whether or not your best people are in the office. Workforce planning is meant to account for third-party arrangements that need managing, and with VET teacher numbers shrinking, the routines have to be light enough to survive thin capacity.

A practical quarter-one checklist

  • Keep one register of every partner, what they deliver, and who inside your RTO owns the relationship.
  • Set a fixed data schedule and format for each partner, and track on-time arrival as a metric.
  • Bring partner assessment and training samples into your own validation and moderation cycle.
  • Test your complaints and feedback pathway from the partner's side. Can a learner of theirs reach you?
  • Define what counts as a significant event at a partner, and who tells whom, and by when.
  • Write down the oversight process so it survives staff turnover.
Checklist of six routine oversight actions an RTO operations leader can set up for third-party partners this quarter

None of that is exotic. The test is whether the evidence exists in one place when your CEO sits down to sign.

Our take

The sector talks about subcontracting as a contract and risk question. It is mostly an operations question. Contracts allocate responsibility between you and a partner, but ASQA has already allocated it to you.

So the COO's job isn't to decide whether partners are risky. It's to make partner activity as visible as your own, on the same cadence, in the same quality loop. If a partner's data, complaints and assessment practice are harder to see than your own, you're signing a declaration you can't fully stand behind.

The RTOs that handle the move to quarterly reporting best won't be the ones with the most people chasing spreadsheets. They'll be the ones where oversight is routine enough that nobody has to remember to do it.

Key takeaways

  • Subcontracting transfers delivery, not accountability. ASQA states RTOs are responsible for managing their third-party arrangements.
  • The CEO's Annual Declaration on Compliance covers third-party services and is expected to rest on verified third-party systems, practices and processes.
  • The 2025 Standards require complaints and feedback capture about third parties, so that process must work across partner boundaries.
  • Quarterly, status-based VET Information Standard reporting will expose late or inconsistent partner data faster than annual AVETMISS did.
  • Oversight that lives in individuals' heads isn't oversight. Document it and build it into routine operations.

FAQ

Does the CEO's declaration really cover our subcontracted delivery?

Yes. ASQA's Accountability Practice Guide says preparation for the Annual Declaration on Compliance must cover the whole scope of registration, including all services delivered by third parties. It also says the CEO completes the declaration having verified the compliance of those third parties' systems, practices and processes.

What is the main RTO subcontractor compliance risk ASQA has flagged?

Unmonitored arrangements. ASQA's 2025-26 environmental scan reported outsourcing of onshore training and assessment to offshore third parties, with risks to quality, currency and consistency and more complicated oversight. Its Information Practice Guide also lists inadequate oversight of third parties that market to or recruit students.

Do complaints about a partner have to come through our process?

The 2025 Standards require providers to capture feedback and complaints about the organisation, any third parties, and any person employed or contracted by the organisation. In practice, learners of your partners need a pathway that reaches you.

How does the VET Information Standard change partner reporting?

NCVER describes a move from minimum annual, point-in-time reporting to minimum quarterly, status-based reporting with new validation and data quality rules. I found no authoritative guidance on how subcontracted activity is split between the RTO and the third party, so confirm that with NCVER and your STA if one applies.

Here is a first step for this week. Pick your largest partner and ask your team to show, in under ten minutes, what that partner delivered last month and where the evidence sits. If the answer is "let me check with Sam", you've found your next project.

Share

See VETos on your own scope.

A 30-minute walkthrough — bring a unit of competency and watch a validation-ready draft take shape.

VETos is coming to the UK.

Join the early-adopter programme and help shape it for FE, ITPs and EPA.

Join the waitlist