A facility manager at a 400,000 sq ft hospital campus asks for your safety records two weeks before renewal. You email last year's OSHA 300 log with every employee name visible, plus a scan of one worker's clinic paperwork, because you wanted to look responsive.
You just disclosed employee information you were not permitted to release, in writing, to a third party. That is the expensive way to fail this evaluation, and it happens constantly because nobody tells cleaning contractors what a client-ready safety report actually contains.
A client-ready safety compliance report contains four things: a signed OSHA 300A annual summary, your TRIR and DART rates with the hours worked behind them, current training and certification records for the crew assigned to that building, and a chemical inventory with matching SDS. Names come off the 300 log before it leaves your office.
Below are nine tests to run on the packet before it goes out, ordered so the cheapest and fastest failures kill a bad report first. Each one tells you what a pass looks like and what a fail actually costs you.
What clients actually mean when they ask for a safety compliance report
"Send us your safety compliance report" is not a defined document. It is a facility manager, a risk manager, or a procurement analyst asking three different questions at once: are you legally clean, are you statistically safe, and are your people trained for my building.
Part of the reason they ask is that they may share liability. Under OSHA's multi-employer citation policy, a building owner or property manager who controls the site can be cited as the controlling employer for hazards created by a contractor. Your safety paperwork is their paperwork.
| Document | What it proves | Who typically asks | Refresh cadence |
|---|---|---|---|
| OSHA Form 300A annual summary | You keep records and a company executive certified them | Risk manager, procurement | Annually, certified and posted Feb 1 to Apr 30 |
| OSHA Form 300 log, names removed | Nature and pattern of recordable injuries | Risk manager, legal | Annually, or on request |
| TRIR and DART worksheet | Injury rate against hours actually worked | Procurement, insurance broker | Annually, some clients quarterly |
| Training and certification roster | The people in the building are trained for it | Facility manager | Monthly or on crew change |
| Chemical inventory plus SDS | What you are bringing into their building | Facility manager, EHS | On product change, verified annually |
| Written programs: HazCom, bloodborne pathogens, PPE assessment | The program exists on paper, not just in your head | EHS, hospital and lab clients | Reviewed annually |
| Certificate of insurance plus EMR letter | Financial backing and workers comp loss history | Procurement, always | Annually at policy renewal |
Run these 9 tests before the report leaves your office
Test 1: Are you even required to keep an OSHA 300 log?
Employers with 10 or fewer employees at all times during the previous calendar year are partially exempt from routine recordkeeping under 29 CFR 1904. Partial exemption by industry is a separate list, Appendix A to Subpart B, and janitorial contractors should verify their NAICS code against it rather than assume.
Pass: You know your headcount trigger and your NAICS code, and you can say in one sentence why you do or do not keep a 300 log.
Fail: You are above 10 employees and have no log. Stop the report. Sending a fabricated or backfilled log to a client is worse than telling them you are building the program now.
Test 2: Is the 300A certified by an actual company executive?
The annual summary is not valid because you printed it. A company executive must certify it: the owner, a corporate officer, the highest ranking company official working at that establishment, or that person's immediate supervisor. It must be posted from February 1 to April 30.
Pass: Signature block filled in, title listed, date on it, and the totals on the 300A match the log.
Fail: An unsigned 300A, or one signed by your office administrator. A procurement reviewer who has seen a hundred of these will spot it, and it makes every other number in your packet suspect.
Test 3: Have the employee names been removed from the log?
This is the test that gets skipped and the one with real consequences. If you voluntarily disclose OSHA forms to anyone other than government representatives, employees, former employees, or their authorized representatives, you must remove or hide employee names and other personally identifying information.
Your client is not on that list. Certain injuries are also privacy concern cases where the name never goes on the log at all.
Pass: Column B is blank or shows case numbers only, and no medical documentation, clinic note, or workers comp claim file is attached.
Fail: Any employee name, address, or medical record in the packet. Pull it back and reissue. Also delete the original from your sent folder so nobody re-forwards it next year.
Test 4: Do your TRIR and DART tie back to real payroll hours?
The formula is fixed: recordable cases multiplied by 200,000, divided by total hours actually worked. The 200,000 represents 100 full-time employees working 40 hours a week, 50 weeks a year. DART uses the same denominator but counts only cases with days away, restricted duty, or job transfer.
Work a real example. Cascade Building Services runs 34 employees across a mix of night offices and medical suites. Payroll shows 58,400 hours actually worked last year, excluding PTO and holidays. They had 2 recordable cases, one of which involved days away.
- TRIR: (2 x 200,000) / 58,400 = 6.85
- DART: (1 x 200,000) / 58,400 = 3.42
Those figures are illustrative, built from the stated assumptions. Compare your own result to the published incidence rate for your industry code in the BLS Survey of Occupational Injuries and Illnesses rather than to a number a competitor quoted you.
Pass: The hours in your denominator come from clocked payroll hours and reconcile to the payroll figure your workers comp auditor used.
Fail: You used scheduled hours or a headcount estimate. Padding the denominator lowers your rate, and the first sharp risk manager who compares it to your comp audit payroll will assume you did it on purpose.
Test 5: Does the chemical list match what is actually in the janitor closet?
Walk the closet before you send the list. Under the Hazard Communication Standard, 29 CFR 1910.1200, you need a chemical inventory and safety data sheets readily accessible to employees on every shift, including the night crew that never meets a supervisor.
Pass: Every labeled bottle in that building appears on the inventory, every product on the inventory has a current SDS, and secondary spray bottles are labeled with the product name and hazard information.
Fail: An unlabeled bottle of decanted disinfectant, or a product the distributor discontinued two years ago still on your list. Both tell the client your paperwork and your operation are two different things.
Test 6: Can you produce a training record for every name on that building's schedule?
Not a company-wide training summary. The specific people who badge into that building this month. HazCom training is required at initial assignment and whenever a new hazard is introduced. For employees with occupational exposure to blood or other potentially infectious materials, bloodborne pathogens training is required annually, and hepatitis B vaccination must be offered within 10 working days of initial assignment.
Pass: A one page roster with name, hire date, each required training topic, completion date, and next due date. Nothing expired.
Fail: Three of the six people currently cleaning the building are not on the roster because they were added after your last training cycle. Fix the crew, then send the report.
Test 7: Is the report scoped to the establishment or to their building?
Here is where most contractors get confused and clients get frustrated. Recordkeeping is done by establishment. For employees who do not report to a fixed location and work at customer sites, records are kept at the office from which they are paid or supervised, not at each client building.
So there is no such thing as "the OSHA 300 log for your building." What you can produce is a site-level incident summary drawn from your own records.
Pass: The packet includes the company 300A at the establishment level plus a short site summary listing incidents, near misses, and corrective actions specific to their address.
Fail: You either refuse the site question outright or you invent a building-specific 300 log. Explain the establishment rule in two sentences and give them the site summary instead. Clients respect the contractor who knows the rule.
Test 8: Does every incident on the report show a closed corrective action?
A client reading your log does not panic at two recordable injuries. They panic at two recordable injuries with no evidence anything changed afterward.
Pass: Each incident line has a root cause, a corrective action, an owner's name, a completion date, and a verification note. "Slip on wet lobby tile, wet floor sign protocol retrained 3/14, verified by supervisor 3/21" reads like a company that runs a program.
Fail: Blank corrective action fields, or the same injury type appearing three times in twelve months with no change in procedure. That pattern is what turns a routine review into a request to rebid.
Test 9: Can you deliver it on their channel, on their date, without being chased?
The last test is operational, not regulatory. A safety report that arrives late, from a personal email address, as an unnamed attachment called scan001.pdf, undoes the credibility of the other eight tests.
Pass: Files named to a convention such as ClientName_300A_2025.pdf, delivered on a fixed calendar date through the channel the client specified, whether that is their vendor portal, a named distribution list, or your client dashboard. You keep a dated record of what was sent to whom.
Fail: The client had to ask twice. In a competitive rebid, a facility manager who chased you for safety documents will remember that longer than they remember your inspection scores.
The printable pre-send checklist
Safety Compliance Report: Pre-Send Checklist
- Recordkeeping obligation confirmed against headcount and NAICS code
- 300A totals reconcile line by line to the 300 log
- 300A certified by owner or officer, with title and date
- All employee names and identifying details removed from any 300 log copy
- No medical records, clinic notes, or comp claim files attached
- Privacy concern cases entered as case numbers, not names
- TRIR and DART recalculated from clocked payroll hours, PTO excluded
- Hours worked figure matches the payroll number used in the comp audit
- Chemical inventory verified against the actual closet in that building
- Current SDS on file for every listed product, accessible on night shift
- Secondary containers labeled with product name and hazard info
- Training roster covers every employee currently assigned to the site
- No expired certifications on the roster
- Site-level incident summary included alongside the company 300A
- Every incident shows root cause, corrective action, owner, and verification date
- COI current, correct additional insured wording, matching legal entity name
- Files named to convention and sent on the agreed channel and date
- Copy of exactly what was sent archived with the date and recipient
What to do when a client asks for something you should not send
It happens on maybe one account in ten. A risk manager asks for the unredacted log, the injured employee's name, or the comp claim file for a specific incident in their lobby.
Do not argue and do not stonewall. Reply in writing with the rule and an alternative: you are restricted from disclosing employee identifying information on OSHA forms to third parties, and you can provide the case number, injury type, body part, days away, and full corrective action instead.
If the request involves an incident on their property that may become a claim, route it to your insurance carrier and your attorney before you send anything. Carriers have a standing interest in what you put in writing about an open claim.
How often should you send safety reports to a commercial cleaning client?
Three cadences cover almost every account. A monthly one page site summary for buildings with an on-site EHS function, a quarterly summary for standard commercial accounts, and an annual full packet at renewal for everyone.
Anchor the annual cycle to the dates the regulation already gives you. The 300A is certified and posted from February 1 through April 30 each year. Establishments covered by the electronic submission rule under 29 CFR 1904.41 must submit by March 2, and the designated industry list and size thresholds are worth verifying for your own establishment.
Send the client packet in the same week you certify the 300A. The data is already assembled, and arriving in February rather than at the client's request in October makes you the vendor who is ahead of the paperwork.
Frequently asked questions
Do I have to give a client my OSHA 300 log if they ask?
No federal rule requires you to hand OSHA forms to a customer. Employees, former employees, their representatives, and government representatives have access rights. Clients do not. Most contracts create the obligation instead, so check what you signed. If you do share voluntarily, you must remove employee names and identifying information first.
Can a client require my EMR to be below 1.0?
Yes, and many RFPs do. The experience modification rate is calculated by NCCI or an independent state rating bureau, with 1.0 representing the expected loss experience for your class and payroll. Above 1.0 means worse than expected. Request the official rating worksheet from your carrier or broker rather than typing the number into a letter yourself.
What do I send if we had zero recordable injuries last year?
Send the certified 300A showing zeros, plus the TRIR calculation showing 0.00 with your actual hours worked in the denominator. Zero with no hours behind it looks like an empty form. Include the training roster and corrective action log for near misses, which demonstrates the zero came from a program rather than from luck.
How long do I have to keep OSHA injury records and training records?
OSHA forms 300, 300A, and 301 must be retained for five years following the end of the calendar year they cover. Bloodborne pathogens training records are kept for three years. Employee medical and exposure records fall under 29 CFR 1910.1020, generally the duration of employment plus 30 years.
Who signs the 300A if I am the owner and the only manager?
You do. The certification must come from an owner, a corporate officer, the highest ranking company official working at that establishment, or that person's immediate supervisor. A sole owner signing as owner satisfies it. Include your printed title and the date, because an unsigned or undated summary is the single most common defect reviewers catch.
Where CleanTrack360 fits
Most of these nine tests fail for the same reason: the records live in four places. Training dates in a spreadsheet, hours in payroll, incidents in a text thread, inspection photos on somebody's phone. CleanTrack360 keeps training and certifications, quality inspections with photo evidence and automatic scoring, and clock-in and clock-out records in one place, and reports export to CSV so you can build the hours-worked denominator for your TRIR calculation without reassembling it by hand.
The browser-based client dashboard also gives your client a standing view of schedules, inspection reports, and service requests, which cuts the volume of ad-hoc "can you send us documentation" emails that arrive the week before a renewal. Plans start at $99 a month for up to 5 team members, and there is a 14-day free trial with no credit card required.