Platform and software
Contractor controls in Mexico: site access and service entries
Two operational controls that close the contractor loop in Mexico: gate access tied to a compliance verdict, and service entries approved with a checklist and segregation of duties.

Contractor risk in Mexico is usually discussed as a documents problem — registrations, opinions, filings. But documents describe the risk; operations admit it. The two moments where a contractor actually touches your business are physical — the moment its workers walk through your gate, and the moment its finished work is approved for payment. A control system that stops at the vendor file leaves both doors open.
Why the vendor file is not enough
Under Mexico's subcontracting regime, the client inherits exposure from non-compliant specialized-services providers — the mechanics are covered in our REPSE guide for foreign companies. Most companies respond with a documentary control. They collect the evidence, track the expirations, gate the payments.
Necessary, and incomplete. A provider's compliance can lapse mid-contract, after onboarding and before the next payment run. During that window its workers are still on your site, generating labor and safety exposure shift by shift. And at the other end of the cycle, invoices arrive for work that someone must attest was actually performed — an attestation that, done informally, dissolves exactly when an auditor asks who verified what.
The operational answer is to put the compliance rule inside the two workflows where the contractor meets the business.
Control one: the gate
The principle is simple to state. Only workers from compliant providers enter the site.
In practice, each contractor worker holds an access pass that exists only because the compliance engine minted it — provider compliant, worker registered, requirements for that site met. Each site defines its own access requirements, so a plant that demands specific HSE documentation enforces that too, through the same pass. The guard scans the pass and sees a verdict, not a document list. Green, the worker enters. Anything else, the worker waits and the provider resolves.
Three design details carry the weight.
The pass is signed. Each pass is cryptographically signed, so a screenshot or a forwarded image does not get anyone through. The gate verifies the signature, not the pixels.
The gate works offline. Signature verification runs against a distributed public key, so a checkpoint with no connectivity applies the same rule. Remote sites — where contractor discipline is hardest — keep the control.
The verdict is computed upstream. The guard makes no judgment about documents. When a provider falls out of compliance, its workers' passes stop being valid; the rule enforces itself at the point of entry.
The effect on providers is worth naming. When site access depends on compliance, contractors stop treating document requests as paperwork from procurement — the incentive moves to their side of the table.
Control two: the service entry
At the end of the cycle sits the approval that turns work into money: the service entry — the acta de servicio, in Mexican operations — recording that a contracted service was received as agreed.
Approved informally, by email or signature-on-PDF, this step produces payments no one can later defend. Approved as a control, it produces the connection every audit needs: this invoice, this work, verified by this person on this date.
The control has three parts.
A checklist before approval. The approver confirms the defined items — scope, quantities, evidence of execution — against a breakdown of the work, not a lump sum. What was checked is recorded with the approval.
Segregation of duties. Whoever submits the record does not approve it; whoever approves does not capture it. One person controlling both ends of the approval is the classic weakness internal audit flags first.
The ERP entry as the outcome. On approval, the service entry sheet is created in your SAP — the connector to your ERP is implemented during rollout, as part of onboarding. The approved record and the payment authorization stay one object, with an audit trail from checklist to entry sheet.
Around the approval, signals advise. An amount outside the pattern for that contract, a photo that repeats from a previous entry — these are flagged to the approver, who decides. Signals do not block, and they are not a fraud verdict; they put the anomaly in front of the person accountable for the decision.
The same structure carries project work. Progress claims from construction and maintenance contractors — the estimaciones of Mexican site practice — pass through the identical sequence of breakdown, checklist and segregated approval, so long-running contracts accumulate the same evidence trail as one-off services.
One loop, three checkpoints
Assembled, the contractor lifecycle runs through three checkpoints: compliance validated before the purchase order and the payment, access granted only against a green verdict at the gate, and work approved through a controlled service entry that lands in the ERP. Each checkpoint generates its own evidence as it runs, which is what makes the whole loop auditable without a reconstruction project.
This is the shape of Vigía Legal's service-entry and site-access controls. If your Mexican operation runs on contractors — maintenance, projects, logistics, security — the loop is worth seeing end to end on your own workflows, with your own sites and approval chains in the model.
Vigía Legal
Validate each provider's REPSE compliance before the PO and the payment, integrated with your ERP.
Book a demoFrequently asked questions
- Why tie plant access to contractor compliance?
- Because the gate is where exposure becomes physical. A worker from a non-compliant contractor who enters your site creates labor, social-security and safety exposure with every shift. If access passes are minted only for workers of compliant providers, the compliance rule enforces itself at the turnstile — green means enter, and the guard needs no judgment call.
- What is a service entry sheet and why does it matter?
- It is the record in your ERP stating that a contracted service was received, which authorizes the invoice for payment. Skipping controls at this step means paying for work nobody verified. Approving it with a checklist, a breakdown of the work and segregation of duties connects each payment to received work — the connection a tax or internal auditor asks you to prove.
- Does the site-access check work without an internet connection?
- Yes. Access passes are cryptographically signed, and the gate can verify a pass's signature offline against a distributed public key. Remote sites with poor connectivity keep the same rule: no valid pass, no entry.
- Do these controls block operations when something looks unusual?
- The access gate blocks: no compliant provider, no pass. Signals on service entries do not — an amount outside the usual pattern or a repeated photo is flagged to the approver, and the person decides. The design principle is that hard rules gate, and anomalies advise.
Keep reading