When a client asks you to evidence a crew, the answer is either a filter on live records or two weeks of inbox archaeology. The difference is decided months earlier.

The email

It arrives on a Tuesday, usually. The client's contract compliance team, or their auditor, or a regulator working through the client, sends a request that is entirely reasonable and lands like a hand grenade:

Please provide evidence of inductions, medicals and relevant competencies for all personnel who worked on the crusher relocation between February and May, including verification of currency at time of work.

In one kind of organisation, a coordinator opens a system, filters by project and date range, exports a register with every worker, every requirement, every document and every validity window, attaches it, and replies before lunch. Total elapsed time: under an hour, most of it spent on the wording of the email.

In the other kind of organisation, the request triggers a two-week expedition. A working group forms. Spreadsheets are recovered from personal drives and compared, discovering they disagree. Someone searches an inbox for "medical" and gets 4,000 results. Certificates are found as photos of cards, taken on utes, at angles. Three workers turn out to have been engaged through a labour hire firm that must now be chased for its own records. The final pack is assembled the night before the deadline, and everyone involved privately knows that if the auditor pulls one more thread, another expedition begins.

Both organisations did, broadly, the same physical work with similarly qualified people. The difference is not diligence and it is not how much anyone cares about compliance. The difference is architectural, and it was decided months or years before the email arrived, by people who were not thinking about audits at all.

Archaeology is the symptom, not the disease

Call the second scenario what it is: inbox archaeology. Skilled professionals excavating their own organisation's past, reconstructing from fragments what the organisation itself did, recently, on purpose. The absurdity is worth pausing on. Nobody is being asked to produce new information. Every document requested was created, sent, received and acted upon. The organisation demonstrably possessed all of it. What it lacks is not the records but the arrangement of the records: a structure in which each fact is attached to a person, a date and a requirement, in one place, queryable.

And this is why the standard responses to a painful audit fail. The post-audit action list always says things like "improve document management" and "staff to file certificates in the shared drive." These treat archaeology as a tidiness problem. It is not. A tidier dig site is still a dig site. The disease is that compliance evidence is stored as communications, in emails, attachments and folders, when it needs to be stored as data: structured records with owners, statuses and dates, born queryable at the moment the work happens.

The distinction sounds technical but it is really about time. A communication answers the question it was sent for, once. A record answers questions forever, including questions nobody had thought of when it was created. The February medical certificate, as an email attachment, answers "did the medical get done?" in February. The same certificate, as a structured record, answers the auditor's question in June, the mobilisation query in August and the incident investigation in November, without anyone touching it again.

Audit-readiness is a by-product, not a project

Here is the reframe this piece exists for: you do not prepare for audits. You run operations in a way that makes audits trivial, and audit-readiness falls out of the side of it, free.

Consider what the effortless organisation from the opening actually did. It did not maintain a parallel "audit file." It simply ran mobilisation, training and site access through systems of record, and the audit answer is a view of the same data the operation runs on daily. The register it exported in an hour is the register its coordinators use every morning to decide who can fly. The evidence is credible precisely because it is not an artefact prepared for the auditor. It is the living record, filtered.

This is also why "audit preparation" as a discrete activity should be treated as a red flag rather than a virtue. If your organisation needs a fortnight to demonstrate what it did, that fortnight is measuring the distance between how you operate and how you record operating. Auditors, the experienced ones, know this instinctively. A pack that arrives in a day, internally consistent, from a live system, gets a lighter touch, because it signals control. A pack that arrives at the deadline, hand-assembled, gets its threads pulled, because hand-assembly is where errors and omissions live. Speed of evidence is itself evidence.

There is a commercial edge to this that gets underweighted. Contractors compete on safety and compliance credibility as much as on rates, and clients remember which partners made their own audit obligations easy. Being the contractor whose records arrive same-day is a quiet, compounding differentiator, in prequalification, in contract renewals and in the tone of every difficult conversation. Trust built on receipts is cheap to maintain and expensive for competitors to copy.

The decisions that were made months earlier

If the difference between an hour and a fortnight is decided in advance, it is worth naming the actual decisions, because each one is small and none of them is labelled "audit."

Where a document goes when it arrives. A certificate lands in an inbox. Someone either forwards it into a folder, which is archaeology-in-waiting, or enters it against the worker's record with its expiry date, which is a query answered forever. Thirty seconds of data entry at the moment of receipt, versus twenty minutes of excavation per document later, multiplied by every document, forever. Almost every audit fortnight is just this decision, made wrongly, thousands of times.

Whether identity is managed or improvised. Half of archaeology is matching: is "M. Sullivan" in the sign-in records the Michael Sullivan in the training matrix and the Mick Sullivan the labour hire firm invoiced? One worker, one identifier, used across mobilisation, training, access and payroll, sounds like bureaucratic fussiness right up until you need to join those histories under pressure.

Whether subcontractor evidence is collected on engagement or on demand. The labour hire crew that must be "chased for records" in June should have had those records attached as a condition of walking on in February. Evidence at the point of engagement is a checkbox in a process. Evidence on demand, months later, from a firm whose contract has ended, is a negotiation.

Whether anything records validity over time. Auditors do not ask whether a worker holds a ticket. They ask whether the worker held it on the day of the work. A filing system, however tidy, stores documents. Only a system that stores dates, issue, expiry, verification, can answer point-in-time questions without a human reconstructing a timeline by hand. This single capability, date-aware records, is most of the difference between the filter and the fortnight.

None of these decisions costs much at the moment it is made correctly. All of them are brutally expensive to make retroactively, which is what an audit fortnight actually is: retroactive data entry, performed under deadline, by your most senior people, at the worst possible hourly rate.

Starting from where you are

No operating business gets to pause and rebuild its records from scratch, so the practical path is narrower and more useful.

Draw a line in time. From a chosen date, every new compliance document enters a structured record with an owner and an expiry, no exceptions, even if the "system" on day one is a rigorously kept register. The backlog behind the line gets remediated opportunistically, crew by crew, as workers mobilise, rather than as a heroic one-off project that will not survive its second week.

Then run one fire drill per quarter. Pick a project and a date range at random and attempt the opening email's request against your own records, timed. The first attempt will be humbling. That is the point. The gap between your drill time and "before lunch" is a measurable, improvable number, and it is a far better compliance KPI than most of what appears on dashboards, because it measures the system's actual ability to prove itself.

And when the client's email does arrive on a Tuesday, notice what it is really asking. Not "are you compliant?" but "can you demonstrate control?" Those are different questions. The fortnight organisation may well be compliant, its people trained, its medicals done, and still fail the second question in the only way that counts, slowly.

The work either proves itself in an hour, or your best people spend two weeks proving it by hand. Same work. Same records. The only variable is whether anyone arranged them before the question arrived, and that variable is available to you today, months ahead of the email, at the price of thirty seconds per document.

Audit week should be a query. Everything else is archaeology, and archaeology is a fine profession that has no business appearing on a contractor's timesheets.