TL;DR: Most manufacturing companies govern the people they employ and, since the OSH Code, the contract workers inside their own gates. Far fewer govern the people who make their product in someone else’s factory: the contract manufacturer, the job worker, and the labour contractors and sub-contractors those firms rely on. That is the org chart nobody draws, and it is where the people risk concentrates. Contract workers already make up 42% of all workers in India’s factories, according to the Annual Survey of Industries 2023-24, up from 38% in 2019-20. The statutory chain of responsibility runs from contractor to principal employer; it does not follow the work through every tier. What reaches the brand further up is commercial and reputational exposure, and the only tools that reach it are contractual: audit rights, wage verification, sub-contracting controls and a named owner inside the company.

This is Part 3 of a three-part series on the people crisis in Indian manufacturing. Part 1 looked at the knowledge walking out of the gate as a generation of senior engineers retires. Part 2 looked at why the next generation is not choosing the shopfloor. It closed with a promise: to examine the people governance gaps inside outsourced and contract manufacturing, and why the organisations least visible on an org chart are often the ones carrying the most risk.

I have sat in enough plant reviews to know how the conversation usually goes. The leadership team can name every department head, every shift supervisor and, increasingly, every licensed contractor working on site. Then someone asks who actually made the components that arrived from the vendor in another district last month, who employed those workers, whether they were paid, and whether anyone has ever checked. The room goes quiet. The honest answer is that nobody drew that part of the chart.

The shift that matters is simple to state. A growing manufacturer stops being a factory and becomes a network of factories working for it. The people function usually stays focused on the first and ignores the second.

Why the Least Visible Name in Your Supply Chain Carries the Most Risk

Risk concentrates where visibility is lowest, and in manufacturing that is almost always further down the chain. The International Labour Organization’s 2016 report on decent work in global supply chains describes the pattern precisely: the subcontracting of labour, through labour contractors and intermediaries, often mirrors the subcontracting of production. A buyer may have contracts with its upper-tier suppliers, while subcontracted lower-tier suppliers often have no formal contractual relationship with the buyer at all. The same report notes that second- and third-tier firms, most of them small enterprises, often employ workers informally, and that this is where the biggest decent work deficits tend to sit.

Three features make the lower tiers risky:

  • They are small. Small suppliers have thinner HR capacity, weaker records and less room to absorb a wage revision or a compliance cost.

  • They are unnamed. The buying company often cannot list who its tier-two suppliers are, let alone which labour contractors they use.

  • They are under pressure. Price, lead time and volume requirements set by the buyer flow down the chain, and labour cost is usually where a small supplier finds its margin.

Concentration adds another dimension. The same ILO report records that, as of 2012, global electronics lead firms had consolidated up to 80% of their production outsourcing into only five contract manufacturers. That is a global and dated example, not an Indian one, but the lesson travels: once a large share of output depends on a few outsourced sites, a people failure at one of them becomes a business continuity problem, not just a compliance one.

The Org Chart Nobody Draws: Who Actually Employs the Person on Your Line

The first governance question is not “are we compliant?” but “who employs each person whose work ends up in our product?” In a typical Indian manufacturing network, the answer runs across several layers:

Layer Who it is Who employs the workers How visible it usually is
Your own plant Your company You, directly Fully visible
Contract labour at your plant Licensed labour contractors on your premises The contractor, with you as principal employer Visible since the codes, if the registers are kept
Contract manufacturer or job worker A separate company making or processing your goods That company Partly visible, through a commercial contract
Labour contractors at the contract manufacturer Contractors supplying workers to your contract manufacturer The contractor, with the contract manufacturer typically as principal employer Rarely visible
Sub-contractors and their labour Firms your contract manufacturer passes work to Those firms or their contractors Usually invisible

The first two rows are where most governance effort goes, and rightly so. The OSH Code makes the principal employer responsible for welfare facilities for contract workers and liable to pay their wages if the contractor fails to. The Astravise guide to contract labour on the factory floor covers those obligations, the 50-worker threshold and the re-papering of contractor agreements in detail.

This article is about the last three rows. They sit outside your gate, and in most companies they sit outside the people function’s mandate as well.

Contract Manufacturers, CMOs and Job Work: The Layer Most Governance Frameworks Stop At

Not all outsourced manufacturing creates the same governance question. The two models most Indian manufacturers use look similar commercially and very different from a people governance standpoint.

Job work. Section 2(68) of the CGST Act, 2017 defines job work as any treatment or process undertaken by a person on goods belonging to another registered person. You own the material; the job worker processes it. The relationship is often informal, priced per piece or per batch, and spread across many small units. The people risk is volume and fragmentation: dozens of job workers, most of them small, few of them ever visited by anyone from your HR or compliance team.

Contract manufacturing. A contract manufacturer, sometimes called a CMO in pharmaceuticals or an EMS provider in electronics, builds the whole product or a major sub-assembly to your specification. The relationship is usually formal, governed by a master agreement with quality and delivery terms. The people risk is concentration: fewer suppliers, larger workforces, and a heavy dependence on each one.

Job work Contract manufacturing
Who owns the materials You Usually the contract manufacturer
Typical supplier profile Many small units Fewer, larger firms
Typical contract Purchase orders, informal terms Master agreement with quality and delivery schedules
Main people risk Fragmentation and informality Concentration and dependence
What governance usually covers Quality of the processed goods Quality, delivery and sometimes a code of conduct
What it usually misses Everything about the workforce Labour contractors and sub-contractors behind the supplier

Most supplier governance frameworks were built by quality and procurement teams, and they stop at the product. They check specifications, yields and delivery performance. They rarely ask who did the work, under what terms, or through how many hands it passed.

For companies deciding whether to build their own capability or rely on vendors, the Astravise analysis of the manufacturing capability centre explains why a captive operation brings the regulated workplace, and its obligations, inside your own entity.

The Labour Contractor Chain: Where Sub-Contracting Quietly Multiplies Your Exposure

A single contract manufacturing relationship can sit on top of two or three further layers of labour supply that the buying company never sees. A common pattern looks like this: you contract a manufacturer; the manufacturer uses two labour contractors to staff its lines during peak season; one of those contractors sources workers through a smaller sub-contractor in another state. None of those names appears in your supplier master.

The ILO describes this as a triangular employment relationship, where the legal employer is separate from the entity for whom the work is actually carried out. Each additional layer adds distance between the worker and anyone with the capacity, or the incentive, to check that wages were paid in full and on time.

The scale of contract labour in Indian manufacturing makes this more than a theoretical risk. The Annual Survey of Industries shows the ratio of contract workers to total workers in factories rising every year, from 0.38 in 2019-20 to 0.42 in 2023-24.

Sub-contracting multiplies exposure in three ways:

  1. Wage leakage. Every intermediary takes a margin. Where the price paid at the top is fixed, the squeeze lands on the wage at the bottom.

  2. Record gaps. Attendance, wage and deduction records thin out with each layer, which makes any claim about working conditions hard to prove either way.

  3. Accountability gaps. When something goes wrong, each layer can point to the next, and the buying company discovers it has no contractual right to find out what happened.

Social Compliance Audits Are Not Statutory Compliance, and Treating Them as Interchangeable Is the Gap

Two different kinds of check are often confused, and the confusion is where much of the risk hides.

Statutory compliance asks whether a supplier holds the registrations and licences the law requires, maintains the prescribed registers and files its returns. It is a documentary test. A supplier can pass it with a clean set of certificates and still underpay its workers.

A social compliance audit asks what is actually happening to the people doing the work. It typically covers working hours against records, wages paid against wages recorded, overtime and its payment, deductions, age verification, health and safety conditions, grievance mechanisms, and confidential interviews with workers away from supervisors.

Statutory compliance check Social compliance audit
Core question Does the supplier hold the required licences and records? What are working conditions actually like?
Evidence Certificates, registers, returns Records tested against interviews and observation
Who is covered The supplier’s registered establishment Everyone doing the work, including contract labour
What it can miss Underpayment, excessive hours, undocumented workers Anything outside the audited site, including sub-contractors
Typical owner Legal or compliance Procurement, sustainability or HR

Neither is sufficient on its own. The ILO’s 2016 report notes that social auditing has had some success with easily detectable violations, such as those relating to safety, payslips and contracts, but that private audits often fail to detect less visible problems such as discrimination or restrictions on freedom of association. An audit also covers only the site audited. If the work has been passed to a sub-contractor, the audit will not see it.

The practical conclusion is to run both, know what each one can and cannot tell you, and never treat a passed audit at a tier-one supplier as evidence about the tiers below it.

Audit Rights Are a Contract Clause, Not a Compliance Function

No company has a right to inspect a supplier’s workforce simply because it buys from that supplier. The right exists only if the contract grants it. Many job-work arrangements run on purchase orders with no such term, and many contract manufacturing agreements include a quality audit right that says nothing about people.

A contract manufacturing or job-work agreement that takes people governance seriously should include:

  1. A right to audit labour practices, not only quality, covering the supplier’s own workers and any contract labour it uses.

  2. A right to interview workers directly, confidentially and without supervisors present.

  3. Unannounced or short-notice visits, with a defined notice period that does not give time to tidy the records.

  4. Wage verification, requiring the supplier to evidence wage payments, for example through bank transfer records, for the workers engaged on your orders.

  5. Sub-contracting controls, requiring prior written approval before any part of the work is passed on, and flowing the same terms down to any approved sub-contractor.

  6. Disclosure of labour contractors, so the supplier names every contractor supplying workers to the lines that make your product.

  7. Remedy and exit, setting out what happens when a finding is made: a corrective action timeline, a right to withhold payment against verified remediation, and termination for serious or repeated breaches.

  8. An indemnity for losses arising from the supplier’s labour violations, reviewed by counsel for enforceability.

The same logic applies to the contractor policy every growing company needs. The Astravise guide to the five policies every Indian startup should have sets out why the terms on which outside parties work for the company belong in writing from the start.

Brand and Customer Exposure: When the Risk Is Reputational and Commercial, Not Statutory

It is important to be precise about liability here. Under the OSH Code, statutory responsibility for contract workers runs from the contractor to the principal employer of the establishment where they work. Where a contract manufacturer engages contract labour at its own factory, it is typically the principal employer for those workers. A brand further up the chain, which neither employs the workers nor is the principal employer of the establishment, does not automatically inherit that statutory liability under the Code. Whether a particular arrangement makes a buyer a principal employer is a fact-specific legal question and should be tested with counsel.

That does not make the brand safe. Its exposure is of a different kind:

  • Customer requirements. Large customers, particularly export customers, increasingly require suppliers to demonstrate labour standards across their own supply chains. A failure at your tier-two supplier can become your breach of contract with your customer.

  • Supply continuity. A labour dispute, walkout or enforcement action at a concentrated contract manufacturer stops your product, not just theirs.

  • Reputation. The public, investors and customers rarely distinguish between a brand’s factory and its contractor’s factory. The brand’s name is the one on the product.

  • Transaction value. Investors and acquirers diligence supply chain risk. An undocumented network of suppliers and contractors is a finding that affects price and terms.

The right frame for a board is that statutory compliance protects the company inside its own gate, and contractual governance protects it everywhere else.

What the OSH Code Changed, and Where It Stops

The OSH Code, 2020, in force since 21 November 2025, replaced 13 central labour laws, including the Contract Labour (Regulation and Abolition) Act, 1970, with a single statute. It widened the definition of workers to include those employed directly or through a contractor, and it kept the principal employer’s responsibility for contract workers’ welfare facilities and unpaid wages. The Astravise analysis of the four labour codes in practice sets out the wider cost and payroll effects.

What the Code did was consolidate and clarify the direct relationship between a principal employer and its contractors. What it did not do is create a duty that follows the work through every subsequent tier of a supply chain. Each establishment answers for its own contract labour. The governance of the network as a whole is left to the companies that sit on top of it.

That is why the answer to the question “are we compliant?” can be yes for every entity in the chain, while the chain as a whole still carries risk the buying company has never measured.

How Astravise Services Builds Visibility Before It Is Needed

Astravise Services approaches supply chain people governance as part of its Strategic CHRO advisory, because the question is ultimately about who employs the people behind the product and on what terms. People strategy is business strategy, and in a manufacturing network the people strategy has to reach beyond the company’s own payroll. The work follows five steps:

  1. Map every tier. Build the org chart nobody draws: every contract manufacturer, job worker, labour contractor and known sub-contractor involved in making the product, with the approximate workforce at each.

  2. Name an owner. Decide who inside the company owns people risk outside the gate. It is usually shared between procurement and HR, which in practice means nobody owns it until someone is named.

  3. Rewrite the contracts. Add labour audit rights, worker interviews, wage verification, sub-contracting controls and remedy terms to contract manufacturing and job-work agreements, starting with the suppliers the business depends on most.

  4. Separate the two checks. Run statutory compliance checks and social compliance audits as distinct activities, with clear scope, and record what each one did not cover.

  5. Review on a cadence. Refresh the map and the audit findings at least annually and whenever a major supplier, customer or volume change occurs, so the chart stays current.

For companies with a formal risk framework, supplier labour risk belongs in the same risk library as financial and regulatory risk, with an owner, a rating and a review date. The Astravise GCC governance blueprint shows how that risk library and compliance calendar are built for a new entity, and the same structure works for a supplier network.

The three parts of this series have looked at three gaps: the knowledge leaving through retirement, the talent not arriving, and the people outside the gate that nobody governs. Each is a people problem that becomes a business problem when it is left unmanaged. The third is the one most likely to surprise a leadership team, because by definition it is the one they cannot see.

Frequently asked questions

Who is the principal employer in a contract manufacturing arrangement?
The principal employer is the employer of the establishment where contract workers are engaged. Where a contract manufacturer engages contract labour at its own factory, it is typically the principal employer for those workers. The brand that buys from the contract manufacturer is not usually the principal employer for that establishment, although whether a specific arrangement changes this is a fact-specific question for legal counsel.
What is the difference between a principal employer and a contractor?
A contractor supplies workers, or undertakes work through workers it engages, for an establishment. The principal employer is the employer of that establishment. Under the OSH Code, 2020, the principal employer must provide prescribed welfare facilities to contract workers and must pay their wages if the contractor fails to do so, which is why the principal employer has a direct interest in verifying the contractor’s payments.
Is a contract manufacturer’s workforce the client company’s legal responsibility?
Not automatically. Statutory responsibility for contract workers under the OSH Code runs from the contractor to the principal employer of the establishment where they work, which is typically the contract manufacturer. The client company’s exposure is usually commercial and reputational: customer requirements, supply disruption, reputational damage and transaction risk. Contract terms such as audit rights and wage verification are how the client manages that exposure.
What should a social compliance audit cover that a statutory audit does not?
A statutory check confirms registrations, licences, registers and returns. A social compliance audit tests what is actually happening: working hours against records, wages paid against wages recorded, overtime payment, deductions, age verification, health and safety conditions, grievance mechanisms and confidential worker interviews. It should cover contract labour on site, and it should record which sub-contractors and sites were outside its scope.
What audit rights should be written into a contract manufacturing or job-work agreement?
The agreement should give the buyer the right to audit labour practices as well as quality, to interview workers confidentially, and to visit at short notice. It should require wage verification for workers engaged on the buyer’s orders, prior approval for any sub-contracting, disclosure of all labour contractors, a corrective action and payment-withholding mechanism, termination rights for serious breaches, and an indemnity reviewed by counsel.
Does a brand carry liability for labour violations at a supplier’s or contract manufacturer’s factory?
Under the OSH Code, statutory liability for contract workers sits with the contractor and the principal employer of the establishment, not automatically with a brand further up the chain. A brand’s exposure is usually commercial and reputational rather than statutory, unless it is itself the principal employer for that establishment. That exposure can still be significant, which is why brands manage it through contract terms, audits and supplier mapping.

[1][2][3][4][5]

Sources

  1. pib.gov.in ↩
  2. pib.gov.in ↩
  3. pib.gov.in ↩
  4. ilo.org ↩
  5. gstcouncil.gov.in ↩