Governance & Compliance

    AS 5182:2018 Explained: Vendor Credentialing for Australian Healthcare Facilities

    A practical guide to AS 5182:2018 vendor credentialing for Australian healthcare facilities, including risk levels, evidence, governance and ongoing credential management.

    By Elliott Hough — OneCredential Pty Ltd

    Healthcare industry representatives perform a wide range of roles within Australian healthcare facilities, from general sales and education through to technical and clinical support in patient-care and restricted areas.

    AS 5182:2018 Vendor credentialing for healthcare facilities provides an Australian framework for determining the credential requirements that apply to healthcare industry representatives and service providers according to the nature of their role and the areas they need to access.

    Published by Standards Australia in April 2018, the Standard was developed to support patient health, safety and confidentiality while providing a more consistent approach to vendor credentialing across Australian healthcare facilities. For healthcare facilities and industry organisations, applying this framework effectively requires more than establishing an initial set of credentials. It involves risk classification, evidence management, ongoing verification, facility-specific requirements and clear governance over access. (Standards Australia, 2018)

    What is AS 5182:2018?

    AS 5182:2018 is the Australian Standard titled Vendor credentialing for healthcare facilities.

    The Standard was prepared by Standards Australia Committee HE-033, whose represented organisations included healthcare, clinical, infection-prevention and industry bodies such as the Australian Healthcare and Hospitals Association, Australasian College for Infection Prevention and Control, Medical Technology Association of Australia and Medicines Australia.

    Its scope covers the credentialing of healthcare industry representatives and service providers (HCIRs) entering healthcare facilities (HCFs) for business purposes.

    The framework aims to support:

    • patient health and safety;
    • confidentiality;
    • appropriate management of risks associated with representative access;
    • suitable credentials for representatives accessing healthcare environments;
    • greater consistency in vendor credentialing;
    • more efficient credentialing processes; and
    • reduced unnecessary duplication.

    Who does AS 5182 apply to?

    The Standard defines an HCIR as an individual employed by a vendor, or an independent contractor acting for or having a commercial arrangement with a vendor, who seeks access to a healthcare facility to conduct business.

    Examples provided by the Standard include:

    • clinical education specialists;
    • supplier sales representatives;
    • supplier executives;
    • biomedical technicians;
    • delivery personnel;
    • non-employee maintenance personnel; and
    • certain service providers.

    Who does AS 5182 apply to?

    An HCIR may require access to patient-care or procedural areas, although many representatives operate only within general or non-clinical areas.

    Healthcare facilities are also defined broadly. The Standard provides examples including hospitals, clinics, day surgery centres, doctors' offices, aged-care and rehabilitation facilities, outpatient-care centres, pathology laboratories, imaging services and specialised-care centres.

    Who sits outside the scope?

    AS 5182 identifies several categories whose credentialing is intended to be addressed through the healthcare facility's human-resources processes or contractual arrangements.

    These include certain:

    • contracted clinical labour and collaborative partners providing services on behalf of the facility;
    • accredited patient-care personnel; and
    • non-clinical contract labour, such as building contractors and IT or software contractors and consultants.

    Who sits outside the scope?

    Healthcare organisations therefore benefit from clearly defining which external populations are managed through their HCIR credentialing framework and which are governed through workforce, contractor or other internal processes.

    AS 5182 uses a risk-based credentialing model

    A central feature of AS 5182 is that credential requirements are proportionate to the risk associated with the representative's role.

    The Standard considers both what the HCIR will be doing and which areas of the healthcare facility they need to access.

    It establishes three risk levels: low, moderate and high.

    Low risk

    Low-risk representatives generally operate in public, corporate, administration, infrastructure or support areas. Their role does not involve activities such as providing technical assistance, operating equipment, entering patient-care areas or assisting clinical staff in patient-care environments. Examples may include general sales or guest-type activity.

    Moderate risk

    Moderate-risk representatives may provide technical or clinical support and enter general patient-care or clinical-support areas outside restricted areas. Examples given by the Standard include access to general wards, ambulatory-care clinics, pathology or research environments and imaging services. Relevant risks include infection, patient-care outcomes, privacy, confidentiality and reputational impact.

    High risk

    High-risk representatives may undertake technical or clinical-support activities in special patient-care or restricted areas. The Standard provides examples including:

    • operating theatres;
    • intensive care units;
    • emergency departments;
    • neonatal and special-care units;
    • transplant and oncology wards;
    • labour and recovery areas; and
    • other specialised clinical environments.

    High risk

    The associated risk considerations reflect the sensitivity of these environments, including vulnerable patients, infection, privacy and confidentiality and other patient-safety risks.

    What credentials does AS 5182 require?

    The credential requirements increase with the assigned risk level. AS 5182 specifies that higher credential levels incorporate the requirements applicable to lower levels.

    A practical summary is:

    Credential requirements by AS 5182 risk level
    RequirementLowModerateHigh
    Positive identification
    Relevant industry or association code of ethics
    Competency relevant to goods/services and associated safety requirements
    Privacy and personal-data protection requirements
    Hand-hygiene practices
    Current immunisation status
    Requirements specific to restricted areas
    Criminal-record declaration where required by the facility and its risk assessment

    What credentials does AS 5182 require?

    This summary reflects the risk-based credential requirements set out in Table 2 of AS 5182:2018 (Standards Australia, 2018). The framework allows the credential burden to remain proportionate to the representative's activities rather than applying the highest level of credentialing to every person entering a facility.

    What evidence supports credentialing?

    AS 5182 also addresses evidence that can be used to demonstrate conformance with credential requirements. Depending on the requirement, examples include:

    • evidence of identity;
    • records of relevant industry-code training;
    • qualifications or training demonstrating competency;
    • privacy training;
    • hand-hygiene training;
    • immunisation evidence;
    • education or training relevant to restricted healthcare areas; and
    • appropriate records relating to criminal-record screening where this is required.

    What evidence supports credentialing?

    This creates an important governance distinction between the credential requirement, the evidence supporting it, and the resulting credential status. A well-managed credentialing process needs to maintain the relationship between all three.

    For example, a facility may require current hand-hygiene competency for a particular access category. Appropriate evidence can be reviewed against that requirement, and the representative's current status can then be used as part of the facility's access-governance process. Digital credentialing systems can make these relationships considerably easier to administer at scale.

    Healthcare facilities retain control of their own requirements

    AS 5182 provides a national framework while expressly preserving healthcare-facility governance. The Standard states that where a healthcare facility's internal policies or guidelines differ from the vendor-credentialing requirements contained in AS 5182, the healthcare facility's policies and guidelines prevail.

    This provision is particularly important when designing a credentialing system across multiple facilities. A healthcare organisation may need to apply:

    • organisation-wide requirements;
    • facility-specific requirements;
    • department or restricted-area requirements;
    • local policies;
    • additional evidence requirements;
    • manual approval processes;
    • exceptions or escalations; and
    • different access conditions according to risk.

    Healthcare facilities retain control of their own requirements

    The result can be a common credentialing framework with local governance layered over it. For healthcare facilities, this preserves control over who may enter their premises and under what conditions. For representatives and industry organisations, shared credential information can reduce unnecessary repetition while clearly identifying additional facility requirements that need to be satisfied.

    What responsibility does AS 5182 place on vendors?

    The Standard gives vendors an important role in maintaining credential conformity. Vendors are required to keep and maintain records demonstrating that their representatives conform with applicable credentialing requirements.

    The Standard also provides for certification or attestation of conformity to be supplied upon request. That information includes:

    • the HCIR's name;
    • the vendor's name;
    • credential level;
    • evidence or records supporting applicable credential requirements;
    • the name and role of the person authorised by the vendor to perform verification; and
    • the date of the most recent verification.

    What responsibility does AS 5182 place on vendors?

    This creates an accountability structure around credential verification rather than relying solely on a representative's declaration that requirements have been completed.

    Credential status must be maintained

    Credential governance continues after initial verification. AS 5182 requires vendors to ensure their representatives continue to conform with applicable credentialing requirements and specifies periodic verification of conformity every 24 months.

    The identification requirements in the Standard also include a credential expiry date, alongside the HCIR's name, vendor and credential level. Operationally, individual pieces of evidence may require management before the overall credential status is reviewed. Immunisation records, training, company affiliations or other evidence can change or expire according to their own requirements.

    This becomes increasingly important as the number of representatives, companies and participating facilities grows.

    A robust credentialing process therefore benefits from:

    • expiry monitoring;
    • renewal workflows;
    • status changes;
    • verification history;
    • affiliation management;
    • alerts where action is required; and
    • a reliable record of previous credential status.

    Identification and credential visibility

    AS 5182 requires HCIRs seeking facility access to carry identification showing:

    • the HCIR's name;
    • the vendor's name;
    • credentialing level; and
    • credential expiry.

    Identification and credential visibility

    In a modern digital environment, the underlying governance principle can also be supported through current credential status that is available to authorised facility personnel when access is being assessed. This can allow a facility to see the information required to make an access decision while managing sensitive supporting information appropriately.

    The level of document visibility can then reflect the facility's governance needs, privacy considerations and the design of the credentialing arrangement.

    How AS 5182 supports consistent healthcare access governance

    The Standard's foreword identifies several reasons for developing a national framework, including simplification, reduced duplication, lower system costs and protection of individual privacy. Achieving those goals across multiple organisations requires coordination between:

    • representatives;
    • vendors and employers;
    • credential-verification processes;
    • healthcare facilities;
    • facility-specific policies; and
    • access controls.

    How AS 5182 supports consistent healthcare access governance

    A representative may already have completed an applicable credential requirement when attending another participating facility. At the same time, the new facility may have additional policies or access conditions that need to be applied.

    A scalable system can retain verified credential information while presenting each healthcare facility with the requirements and governance controls relevant to its environment. This supports consistency without removing local decision-making authority.

    AS 5182 and the Australian medical technology industry

    AS 5182 also has particular importance for the Australian medical technology sector. The Medical Technology Association of Australia (MTAA) Medical Technology Industry Code of Practice, Edition 14, updated in March 2026, expressly refers to Australian Standard 5182:2018 – Vendor Credentialling for Healthcare Facilities.

    MTAA describes AS 5182 as a separate standard for the conduct of company representatives entering healthcare facilities and states that its member companies are required to comply with it as a condition of MTAA membership. That means the Standard forms an important part of the governance environment for medical-technology companies whose representatives interact with Australian healthcare facilities.

    Other industry sectors may also have relevant association codes or requirements that form part of an HCIR's applicable credential profile.

    Putting AS 5182 into practice

    For a healthcare organisation, practical implementation can be considered as a series of connected governance activities.

    1. Define the HCIR population: Identify the representatives and service providers who fall within the organisation's vendor-credentialing framework.
    2. Determine role and access risk: Establish what each representative does and which areas of the facility they may need to access.
    3. Apply the appropriate credential level: Use the risk classification to determine the baseline credential requirements.
    4. Apply facility-specific requirements: Layer relevant organisational, facility, department or restricted-area requirements over the common credential framework.
    5. Verify supporting evidence: Ensure appropriate evidence supports each applicable requirement and maintain a record of verification.
    6. Maintain current credential status: Manage renewal, expiry, updated evidence, changes in role and changes in company affiliation.
    7. Connect credential status with access governance: Make current credential information available as part of the process used to approve, manage and record representative access.
    8. Maintain auditability: Retain sufficient information to understand how credential and access decisions were made, including verification and historical status where required.

    Putting AS 5182 into practice

    For organisations managing substantial numbers of HCIRs, these activities can create significant administrative complexity when they are spread across spreadsheets, email, document repositories and individual facility processes. A centralised credentialing platform can provide a common governance layer across those activities.

    Supporting AS 5182-aligned governance with OneCredential

    OneCredential has been designed to support Australian healthcare organisations and industry representatives in managing the operational processes that sit around vendor credentialing and facility access.

    The platform brings together elements including:

    • representative identity;
    • company and affiliation information;
    • credential requirements;
    • document and evidence workflows;
    • verification status;
    • credential expiry;
    • risk classification;
    • healthcare-facility requirements;
    • approvals and access controls;
    • check-in and facility-access records; and
    • governance and audit information.

    Supporting AS 5182-aligned governance with OneCredential

    The model allows common credential requirements to be managed consistently while preserving the ability of participating healthcare facilities to establish their own requirements and govern access to their environments. This supports the broader objectives reflected in AS 5182 around consistency, risk-proportionate credentialing, ongoing conformity, facility governance and reduced duplication.

    Explore healthcare vendor credentialing with OneCredential

    See how OneCredential supports healthcare facilities in managing representative credentialing and access governance.

    Sources and references

    • Standards Australia. (2018). AS 5182:2018 Vendor credentialing for healthcare facilities. Standards Australia.
    • Medical Technology Association of Australia. (2026). Medical Technology Industry Code of Practice, Edition 14.

    Learn more about OneCredential

    Explore how OneCredential supports healthcare vendor credentialing and facility access.

    Related resources