Contingent Workforce Compliance: Trust, But Verify

contingent workforce compliance

As your contingent workforce grows, so does your compliance risk. In our recent webinar, Beyond Staffing and the MSP: Rethinking How You Manage a Complex Contingent Workforce,” we sat down with guest expert Jeff Nugent. 

Jeff, who brings more than 25 years’ experience in the contingent workforce and staffing industry, helped drive the early adoption of VMS and MSP technology, and he’s spent the last 15+ years in the employer of record (EOR) and agent of record (AOR) space.  

Here’s a line from the session that particularly stuck with us: 

“Trust, but verify… and to verify, automate it.” 

If your main defenses are contracts, indemnification clauses, and promises like “our vendor says we’re fine,” you might be exposing yourself to some pretty significant risks. Ultimately, courts and auditors care far less about what your paperwork says than about how an engagement actually works day to day. 

Why ‘we have an MSP’ isn’t a compliance strategy 

First, let’s start with the scale of the problem. Roughly one in four U.S. knowledge workers now freelances or works independently, and the gig economy represents about $3.7 trillion in annual spend. Meanwhile, 58% of enterprises with more than 1,000 employees run a managed service provider (MSP) program—up from 40% in 2009. 

MSPs and staffing partners earn their keep. As Jeff noted: 

“The MSP model really works well when there’s need for scale, control, and consistency.” 

What they don’t do is transfer your legal responsibility. It doesn’t matter whether a worker comes to you through an MSP, a statement of work, a purchase order, or a direct contract—if that person is misclassified or managed like an employee, the risk lands on you. 

This is where “trust, but verify” stops being a tidy phrase and becomes an operating rule. 

Here are five compliance checks to run on your contingent workforce before an auditor does, drawn from Jeff’s comments in the session.

1. Business setup: Does this worker actually operate as a business?

The first question to ask about any independent contractor is whether they run an actual business. That means a legal entity where appropriate, real business registrations and tax IDs, and evidence they serve clients beyond you. 

In the session, Jeff framed the whole due diligence exercise this way: 

“You have to get deeper than just hiding behind an indemnification clause and do the proper due diligence on the workers and the engagements. Do they have a business set up? Do they have insurances? And then how they behave is important.” 

You can’t afford to be blind to your vendors and assume every “IC” is properly structured. When someone has no business presence, no other clients, and no commercial structure, they look a lot less like a contractor and a lot more like a solo employee—and that can put you on thin ice. 

The check: Document the business status of each IC, and pay special attention to anyone engaged outside your central program.

2. Insurance: Don’t assume—verify! 

Insurance is one of the clearest signals that someone operates as a genuine business. The questions worth answering: Do they carry appropriate coverage? General liability? Professional liability or errors and omissions, where the work calls for it? Any jurisdiction-specific requirements? 

“Trust, but verify” applies here as directly as it gets. A contract clause promising a worker “will be insured” isn’t proof of anything. 

The check: Collect proof of insurance from ICs and SOW providers, store it centrally, and track expiration dates the same way you’d track a license or certification.

3. What courts actually look at: behavior over paper

Courts don’t stop at the contract. They look at how the engagement behaved:  

-Who directs the work day to day?  

-How tightly are hours and locations controlled?  

-Is the worker integrated like a permanent employee?  

-Do they carry any real commercial risk? 

As Jeff described it: 

“Contracts are nice, but in the courts of law, it’s ‘let’s look at the situation, let’s understand how people are behaving.’ That’s where things get highlighted—that what was written on the contract is very different than what’s happening in that engagement.” 

You can’t paper your way out of a relationship that functions like employment. The label on the contract won’t save you if the facts say otherwise. 

The check: Audit how your contingent workers operate in practice: e.g., reporting lines, tools and system access, working conditions, and the degree of control and integration. If it looks and feels like an employee relationship, documents alone won’t protect you.

4. Documentation and proof: ‘We’re compliant’ isn’t evidence 

Again, auditors and courts expect documentation and proof, not assurances. The weak spots show up in the same places: over-reliance on indemnification clauses; classification decisions buried in email threads; and no repeatable, auditable workflows for IC and SOW decisions. 

Jeff was blunt about the limits of an indemnification clause: 

“The indemnification clause is very thin and will not protect you in a real-life situation. Specifically around litigation, they look at the situation versus what the contracts say—in all cases.” 

Indemnity language can feel like a safety net. But if the facts don’t support your classification, that language won’t hold. 

Here’s what auditors want instead, in Jeff’s words: 

“Audits and the courts need documentation and proof—not just that you said, ‘Oh yeah, I’m compliant,’ and you just trusted your vendor.” 

Importantly, doing this by hand doesn’t scale, though: “That process, when you go through those steps, is manual and ugly if you’re doing it through email and spreadsheets,” he noted. 

The check: Build a standard process for IC classification, SOW-versus-staff-augmentation decisions, and vendor onboarding and review. Capture each decision in a system rather than a spreadsheet, so you can show who made the call, what criteria they used, and when it was last reviewed. At scale, that generally takes technology and a structured compliance framework, not manual effort alone.

5. Workers outside your program carry the same risk

In a lot of organizations, the real exposure is shadow spend: e.g., work moving through SOWs, POs, and side agreements that never touch the formal program. 

There’s a predictable reason for it. As programs mature, they add layers of policy and approval. Managers under pressure to deliver take the path of least resistance: a direct SOW, a simple PO, a one-off contractor engagement, etc. But putting someone on a PO or an SOW doesn’t make the arrangement compliant. 

Jeff put the manager’s incentive plainly: 

“The manager just wants to get work done, and they want to get the talent in as fast as possible. The path of least resistance is what they will take every single time.” 

And the paperwork doesn’t fix the classification: “Just saying they’re an independent contractor and putting them on a PO or putting them on a statement of work doesn’t make them compliant or legal,” he added. 

The risk follows the work regardless of route. You still carry the compliance exposure, especially around IC misclassification. You often carry higher cost, as SOW work can tend to be pricier and less managed. And you lose visibility, because your “official” program can be a fraction of a much larger pool of unmanaged contingent work. 

The check: Map where all external work is actually happening—inside managed programs, through SOWs and POs, and via freelance platforms or ad hoc deals. Then apply the same standards everywhere: business setup, insurance, behavioral tests, and documentation. If someone is doing the work, the liability is yours no matter how they got in the door. 

Compliance as a shared responsibility 

Even with a solid group of external partners—MSPs, EORs, IC compliance tools—you can’t throw compliance over the fence and call it handled. 

As we noted during the session, the strongest partnerships are the ones where both sides stay engaged, rather than one assuming the other has it covered. Partners can absorb the scale and complexity, but the ownership—across HR, legal, and procurement—still has to sit inside your organization, backed by technology that can automate and document the process.  

That’s really the heart of Jeff’s advice: Contracts describe how an engagement is supposed to work, but compliance depends on how it actually works—and on being able to prove it. Or, as he put it when asked how to avoid the next audit surprise: 

“If I can say anything at the end of that question: trust, but verify—and to verify, automate it.” 

That “verify, then automate” step is exactly what All Work is built for. As a combined EOR and workforce management platform, we legally employ your flexible workers and handle payroll, taxes, and compliance in one place. See how it works.