System-Oriented Contract Management: Risk-Based Auditing in Practice

July 15 2026
Team RiskChallenger

More and more clients in construction and infrastructure, such as national road authorities, water boards and provinces, are working with integrated contracts. Under these contracts, the contractor takes on more responsibility for design, execution and quality. But how do you, as the client, keep a grip on quality without inspecting every single bolt yourself? The answer: system-oriented contract management.

In this blog, we explain exactly what system-oriented contract management (SCM) is, how risk-based auditing works and why a solid risk register is the foundation of every successful SCM approach.

What is system-oriented contract management?

System-oriented contract management is a method that lets a client control the quality of a project by relying on the contractor's quality management system. Instead of checking every product and every work step yourself, you assess whether the contractor's system is functioning properly. If that system demonstrably works, you can trust that the end result meets the requirements.

This approach is widely applied to design-and-build contracts, where the contractor handles both the design and the execution. The principle is simple: the contractor demonstrates that it controls quality, and the client assesses that from a distance. Trust where you can, verify where you must.

Why do clients choose SCM?

System-oriented contract management solves a number of classic problems:

  • Efficiency: you don't have to check everything yourself, but instead deploy your audit capacity precisely where the risks are greatest.
  • Clear responsibilities: the contractor is and remains responsible for quality. No duplicate checks, no shifting of liability.
  • Better collaboration: the conversation isn't about ticking boxes, but about the risks that truly matter.
  • Demonstrability: every audit and finding is documented, which allows you as the client to show that you have fulfilled your public and contractual responsibility.

The three types of audits within SCM

Within system-oriented contract management, you work with three types of audits, each at a different level:

1. System audits

Here you assess the contractor's quality management system as a whole. Does the system work as described? Are deviations flagged and followed up on? A system audit builds confidence in the foundation.

2. Process audits

A process audit zooms in on a specific work process, for example the design process or the inspection process on the construction site. You check whether the process runs in practice the way it was documented.

3. Product audits

With a product audit, you inspect a concrete (interim) product, such as a design document, a concrete pour or a delivered installation. You deploy product audits selectively at the biggest risks, not by default on everything.

The art is in the mix: the better system and process audits turn out, the fewer product audits you need. If something stands out, that's exactly when you scale up.

Risk-based auditing: the heart of system-oriented contract management

And here's the most important point: system-oriented contract management stands or falls with a solid risk register. You don't audit randomly, but in a risk-based way. The central question is: where can things go wrong, and what are the consequences if they do?

In concrete terms, that means:

  1. Identify the risks of the project, together with the whole team and preferably the contractor as well.
  2. Prioritize by likelihood and impact, so it's clear which risks deserve the most attention.
  3. Link audits to risks, so every system, process or product audit has a clear rationale.
  4. Update continuously, because risks change over the course of a project. An audit plan that's a year old says little about today's risks.

In practice, we see that this is precisely where things tend to go wrong. The risk register lives in an Excel file maintained by just one person, the audit plan sits separately from it, and the risk conversation between client and contractor gets bogged down in a debate about numbers rather than substance.

Common pitfalls with SCM

From practice, we know a number of recurring pitfalls:

  • Auditing without a risk basis: audits happen because they're required, not because a risk calls for them. This is how system-oriented contract management loses its strength.
  • A static risk register: the register is drawn up at the start and then barely updated. Yet it's precisely the dynamics of the project that determine where you need to audit.
  • Risk management as a solo activity: one risk manager fills in the register while the rest of the team never looks at it. Valuable signals from auditors, technical managers and stakeholder managers go unused.
  • Lack of a shared language: client and contractor each use their own risk list, which makes the conversation about risks run stiffly.

The common thread? System-oriented contract management isn't an administrative exercise, but a continuous dialogue about risks. And that dialogue deserves better support than a spreadsheet.

How RiskChallenger supports your SCM approach

RiskChallenger is built on the conviction that risk management is about the substantive dialogue, and not about the number on the page. That philosophy aligns seamlessly with risk-based auditing within system-oriented contract management:

  • Interactive risk sessions: involve the entire project team and the contractor in identifying and prioritizing risks through QR codes. No accounts needed, everyone joins in.
  • Collaborative quantification: vote live with the team on likelihood and impact, so the prioritization is broadly supported and the conversation stays focused on substance.
  • One up-to-date risk register: no version conflicts or outdated spreadsheets, but real-time insight for everyone who needs it.
  • Dashboards for steering: see at a glance which risks are rising and where your audit capacity is needed most.
  • Automated follow-up: deadlines for control measures are tracked automatically, so commitments from audits don't slip through the cracks.
  • GIS integration: plot risks on the map, which is handy for infrastructure projects where location and surroundings play a big role.

Organizations such as water boards and major contractors already use RiskChallenger to make their project risks both manageable and open for discussion. Our approach is also grounded in ISO 31000, the international standard for risk management.

Conclusion: SCM starts with good risk management

System-oriented contract management is a powerful way to keep a grip on integrated contracts without checking everything yourself. But the method only works if your risk register is current, supported and open for discussion. Those who take risk management seriously get the most out of SCM: targeted audits, a better conversation with the contractor and demonstrable control of the contract.

Do you have any questions about this article?

Feel free to contact us via live chat or via

support@riskchallenger.nl